![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2004-1719 |
Description: | Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail
Server 5.2.7 allow remote attackers to inject arbitrary web script or
HTML via the (1) category, (2) cserver, (3) ext, (4) global, (5)
showgroups, (6) or showlite parameters to address.html, or the (7)
spage or (8) autoresponder parameters to settings.html, the (9) folder
parameter to readmail.html, or the (10) attachmentpage_text_error
parameter to attachment.html, (11) folder, (12) ct, or (13) cv
parameters to calendar.html, (14) an |
Test IDs: | None available |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2004-1719 BugTraq ID: 10966 http://www.securityfocus.com/bid/10966 Bugtraq: 20040817 Vulnerabilities in Merak Webmail Server (Google Search) http://marc.info/?l=bugtraq&m=109279057326044&w=2 http://packetstormsecurity.nl/0408-exploits/merak527.txt http://www.osvdb.org/9037 http://www.osvdb.org/9038 http://www.osvdb.org/9039 http://www.osvdb.org/9040 http://www.osvdb.org/9041 http://www.osvdb.org/9042 http://securitytracker.com/id?1010969 http://secunia.com/advisories/12269 XForce ISS Database: merak-xss(17024) https://exchange.xforce.ibmcloud.com/vulnerabilities/17024 |