4.3
CVSSv2

CVE-2005-2724

Published: 30/08/2005 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 allows remote malicious users to inject arbitrary web script or HTML via a file attachment that is processed by the Display feature. NOTE: the severity of this issue has been disputed by the developer.

Vulnerable Product Search on Vulmon Subscribe to Product

inter7 sqwebmail 3.4.1

inter7 sqwebmail 4.0.4_2004-05-24

inter7 sqwebmail 4.0.5

inter7 sqwebmail 3.5.0

inter7 sqwebmail 3.5.1

inter7 sqwebmail 4.0.6

inter7 sqwebmail 4.0.7

inter7 sqwebmail 3.5.2

inter7 sqwebmail 3.5.3

inter7 sqwebmail 5.0.0

inter7 sqwebmail 5.0.1

inter7 sqwebmail 3.6.0

inter7 sqwebmail 3.6.1

inter7 sqwebmail 5.0.4

Vendor Advisories

Several Cross Site Scripting vulnerabilities were discovered in SqWebmail A remote attacker could exploit this to execute arbitrary JavaScript or other active HTML embeddable content in the web browser of an SqWebmail user by sending specially crafted emails to him ...
Jakob Balle discovered a vulnerability in the handling of attachments in sqwebmail, a web mail application provided by the courier mail suite, which can be exploited by an attacker to conduct script insertion attacks For the old stable distribution (woody) this problem has been fixed in version 0373-26 For the stable distribution (sarge) this ...