PT-2002-2621 · Icewarp · Icewarp Web Mail

Publicado

2002-12-31

·

Atualizado

2008-09-05

·

CVE-2002-1899

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions IceWarp Web Mail versions 3.3.3 through 3.4.5
Description A cross-site scripting issue allows remote attackers to inject arbitrary web script or HTML via the addressname parameter, also known as "Full Name".
Recommendations For IceWarp Web Mail version 3.3.3, update to a version that fixes this issue. For IceWarp Web Mail version 3.4.5, update to a version that fixes this issue. As a temporary workaround, consider restricting the use of the addressname parameter until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1899

Produtos afetados

Icewarp Web Mail