4.3
CVSSv2

CVE-2012-2569

Published: 19/06/2014 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Synametrics Technologies Xeams 4.4 Build 5720 allows remote malicious users to inject arbitrary web script or HTML via the body of an email.

Vulnerable Product Search on Vulmon Subscribe to Product

synametrics xeams 4.4

Exploits

#!/usr/bin/python ''' Author: loneferret of Offensive Security Product: Xeams Email Server Version: 44 Build 5720 Vendor Site: wwwxeamscom Timeline: 29 May 2012: Vulnerability reported to CERT 30 May 2012: Response received from CERT with disclosure date set to 20 Jul 2012 23 Jul 2012: Update from CERT: No response from vendor 08 Aug 2 ...