Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration Suite (ZCS) 4.0.3, 4.5.6, and possibly other versions prior to 4.5.10 allow remote malicious users to inject arbitrary web script or HTML via an e-mail attachment, possibly involving a (1) .jpg or (2) .gif image attachment.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
zimbra collaboration suite 4.0.3 |
||
zimbra collaboration suite 4.5.6 |