4.3
CVSSv2

CVE-2004-2334

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in EMU Webmail 5.2.7 allow remote malicious users to inject arbitrary web script or HTML via (1) a hex-encoded value to the variable parameter in emumail.fcgi, (2) the folder parameter in emumail.fcgi, or Javascript in the (3) username or (4) password field in the login page.

Vulnerable Product Search on Vulmon Subscribe to Product

emumail emu webmail 5.2.7

Exploits

source: wwwsecurityfocuscom/bid/9861/info Multiple vulnerabilities have been identified in the application that may allow an attacker to carry out cross-site scripting attacks and disclose the path to the victim's home directory The issues are reported to exist in the login script, 'emumailfcgi' script and the 'initemu' sample script ...