PT-2006-4128 · Owm · Open Webmail

Jose Alves

·

Publicado

2006-06-27

·

Atualizado

2017-07-20

·

CVE-2006-3233

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Open WebMail (OWM) versions prior to 2.52
Description A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via the from field. This enables attackers to execute malicious scripts on the victim's browser.
Recommendations For Open WebMail (OWM) versions prior to 2.52, update to a version released after 06/18/2006 to resolve the issue. As a temporary workaround, consider restricting input to the from field to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-3233

Produtos afetados

Open Webmail