Vulnerabilities > CVE-2005-3429 - Cross-Site Scripting vulnerability in Rockliffe Mailsite Express 6.1.20

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
rockliffe

Summary

Rockliffe MailSite Express before 6.1.22, with the option to save login information enabled, saves user passwords in plaintext in cookies, which allows local users to obtain passwords by reading the cookie file, or remote attackers to obtain the cookies via cross-site scripting (XSS) vulnerabilities.

Vulnerable Configurations

Part Description Count
Application
Rockliffe
2