Vulnerabilities > CVE-2002-1708 - Unspecified vulnerability in Basilix Webmail 1.1.0

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
basilix
nessus
exploit available

Summary

Cross-site scripting vulnerability (XSS) in BasiliX Webmail 1.10 allows remote attackers to execute arbitrary script as other users by injecting script into the (1) subject or (2) message fields.

Vulnerable Configurations

Part Description Count
Application
Basilix
1

Exploit-Db

descriptionBasiliX Webmail 1.1 Message Content Script Injection Vulnerability. CVE-2002-1708. Webapps exploit for php platform
idEDB-ID:21570
last seen2016-02-02
modified2002-06-19
published2002-06-19
reporterUlf Harnhammar
sourcehttps://www.exploit-db.com/download/21570/
titleBasiliX Webmail 1.1 Message Content Script Injection Vulnerability

Nessus

NASL familyCGI abuses : XSS
NASL idBASILIX_MESSAGE_CONTENT_SCRIPT_INJECTION.NASL
descriptionThe remote host appears to be running a BasiliX version 1.1.0 or lower. Such versions are vulnerable to cross-scripting attacks since they do not filter HTML tags when showing a message. As a result, an attacker can include arbitrary HTML and script code in a message and have that code executed by the user
last seen2020-06-01
modified2020-06-02
plugin id14218
published2004-08-09
reporterThis script is Copyright (C) 2004-2018 George A. Theall
sourcehttps://www.tenable.com/plugins/nessus/14218
titleBasiliX Message Content XSS