Vulnerabilities > CVE-2007-2718
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE Summary
Cross-site scripting (XSS) vulnerability in the WebMail system in Stalker CommuniGate Pro 5.1.8 and earlier, when using Microsoft Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via crafted STYLE tags.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 | |
Application | 1 |
Exploit-Db
description | CommuniGate Pro. CVE-2007-2718. Webapps exploit for php platform |
id | EDB-ID:30027 |
last seen | 2016-02-03 |
modified | 2007-05-12 |
published | 2007-05-12 |
reporter | Alla Bezroutchko |
source | https://www.exploit-db.com/download/30027/ |
title | CommuniGate Pro 5.1.8 Web Mail HTML Injection Vulnerability |
Nessus
NASL family | CGI abuses : XSS |
NASL id | COMMUNIGATEPRO_519.NASL |
description | According to its banner, the version of CommuniGate Pro running on the remote host fails to completely sanitize email messages, when using Internet Explorer (IE). A remote attacker may be able to leverage this issue to inject arbitrary HTML and script code into a user |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 25215 |
published | 2007-05-14 |
reporter | This script is Copyright (C) 2007-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/25215 |
title | CommuniGate Pro WebMail w/ MSIE STYLE Tag XSS |
code |
|
References
- http://marc.info/?l=full-disclosure&m=117900749209206&w=2
- http://www.communigate.com/CommuniGatePro/History51.html
- http://www.scanit.be/advisory-2007-05-12.html
- http://www.securityfocus.com/bid/23950
- http://www.securitytracker.com/id?1018048
- http://secunia.com/advisories/25250
- http://osvdb.org/36017
- http://www.vupen.com/english/advisories/2007/1795
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34266