PT-2004-3594 · Hastymail+1 · Hastymail+1

Publicado

2004-12-31

·

Atualizado

2021-07-23

·

CVE-2004-2704

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Hastymail versions 1.0.1 and earlier Hastymail development versions 1.1 and earlier
Description The issue allows attachments to be rendered inline by Internet Explorer, potentially facilitating cross-site scripting (XSS) and other attacks, due to the absence of the attachment parameter in the Content-Disposition field for attachments.
Recommendations For Hastymail versions 1.0.1 and earlier, consider updating to a version that includes the attachment parameter in the Content-Disposition field to prevent inline rendering of attachments. For Hastymail development versions 1.1 and earlier, consider updating to a version that includes the attachment parameter in the Content-Disposition field to prevent inline rendering of attachments. As a temporary workaround, consider configuring Internet Explorer to not render attachments inline, or avoid using Internet Explorer to access attachments from Hastymail until the issue is resolved.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2004-2704

Produtos afetados

Hastymail
Internet Explorer