4.3
CVSSv2

CVE-2007-5290

Published: 09/10/2007 Updated: 29/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 440
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in MailBee WebMail Pro 3.4 and previous versions; and possibly MailBee WebMail Pro ASP prior to 3.4.64, WebMail Lite ASP prior to 4.0.11, and WebMail Lite PHP prior to 4.0.22; allow remote malicious users to inject arbitrary web script or HTML via the (1) mode parameter to login.php and the (2) mode2 parameter to default.asp in an advanced_login mode.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

afterlogic mailbee webmail

afterlogic mailbee webmail 3.4

afterlogic mailbee webmail 3.2

afterlogic mailbee webmail 3.3

afterlogic mailbee webmail 3.1

Exploits

source: wwwsecurityfocuscom/bid/25942/info MailBee WebMail Pro is prone to multiple cross-site scripting vulnerabilities because the application fails to sufficiently sanitize user-supplied input An attacker can exploit these issues to steal cookie-based authentication credentials and launch other attacks These issues affect MailBee W ...
source: wwwsecurityfocuscom/bid/25942/info MailBee WebMail Pro is prone to multiple cross-site scripting vulnerabilities because the application fails to sufficiently sanitize user-supplied input An attacker can exploit these issues to steal cookie-based authentication credentials and launch other attacks These issues affect MailBe ...