Vulnerabilities > CVE-2004-1669
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Cross-site scripting (XSS) vulnerability in MERAK Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to execute arbitrary web script or HTML via the (1) User name parameter to accountsettings.html or (2) Search string parameter to search.html.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 | |
Application | 3 |
Nessus
NASL family | CGI abuses |
NASL id | ICEWARP_WEBMAIL_VULNS.NASL |
description | The remote host is running IceWarp Web Mail - a webmail solution available for the Microsoft Windows platform. The remote version of this software is vulnerable to multiple input validation issues that could allow an attacker to compromise the integrity of the remote host. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 15469 |
published | 2004-10-13 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/15469 |
title | IceWarp Web Mail Multiple Flaws (1) |
code |
|
References
- http://marc.info/?l=bugtraq&m=109483971420067&w=2
- http://marc.info/?l=bugtraq&m=109483971420067&w=2
- http://secunia.com/advisories/12789
- http://secunia.com/advisories/12789
- http://www.securityfocus.com/bid/11371
- http://www.securityfocus.com/bid/11371
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17313
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17313