Vulnerabilities > CVE-2002-1307 - Unspecified vulnerability in Mhonarc 2.4.4/2.5.12/2.5.2
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Cross-site scripting vulnerability (XSS) in MHonArc 2.5.12 and earlier allows remote attackers to insert script or HTML via an email message with the script in a MIME header name.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Exploit-Db
description | Mhonarc 2.5.x Mail Header HTML Injection Vulnerability. CVE-2002-1307 . Remote exploit for linux platform |
id | EDB-ID:22026 |
last seen | 2016-02-02 |
modified | 2002-11-19 |
published | 2002-11-19 |
reporter | Steven Christey |
source | https://www.exploit-db.com/download/22026/ |
title | Mhonarc 2.5.x Mail Header HTML Injection Vulnerability |
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-199.NASL |
description | Steven Christey discovered a cross site scripting vulnerability in mhonarc, a mail to HTML converter. Carefully crafted message headers can introduce cross site scripting when mhonarc is configured to display all headers lines on the web. However, it is often useful to restrict the displayed header lines to To, From and Subject, in which case the vulnerability cannot be exploited. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 15036 |
published | 2004-09-29 |
reporter | This script is Copyright (C) 2004-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/15036 |
title | Debian DSA-199-1 : mhonarc - XSS |
code |
|
References
- http://www.debian.org/security/2002/dsa-199
- http://www.debian.org/security/2002/dsa-199
- http://www.mhonarc.org/archive/cgi-bin/mesg.cgi?a=mhonarc-users&i=200210211713.g9LHDXE02256%40mcguire.earlhood.com
- http://www.mhonarc.org/archive/cgi-bin/mesg.cgi?a=mhonarc-users&i=200210211713.g9LHDXE02256%40mcguire.earlhood.com
- http://www.osvdb.org/7353
- http://www.osvdb.org/7353
- http://www.securityfocus.com/bid/6204
- http://www.securityfocus.com/bid/6204
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10666
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10666