Vulnerabilities > CVE-2002-1495 - Unspecified vulnerability in Rudi Benkovic Jawmail 1.0/1.0.1/1.0Rc1

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
rudi-benkovic
exploit available

Summary

Cross-site scripting (XSS) vulnerability in JAWmail 1.0-rc1 allows remote attackers to insert arbitrary script or HTML via (1) attached file names in the Read Mail feature, (2) text/html mails that are displayed in a pop-up window, and (3) certain malicious attributes within otherwise safe tags, such as onMouseOver.

Vulnerable Configurations

Part Description Count
Application
Rudi_Benkovic
3

Exploit-Db

descriptionRudi Benkovic JAWMail 1.0 Script Injection Vulnerability. CVE-2002-1495. Webapps exploit for php platform
idEDB-ID:21817
last seen2016-02-02
modified2002-09-23
published2002-09-23
reporterUlf Harnhammar
sourcehttps://www.exploit-db.com/download/21817/
titleRudi Benkovic JAWMail 1.0 Script Injection Vulnerability