PT-2002-2621 · Icewarp · Icewarp Web Mail

Published

2002-12-31

·

Updated

2008-09-05

·

CVE-2002-1899

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions IceWarp Web Mail versions 3.3.3 through 3.4.5
Description A cross-site scripting issue allows remote attackers to inject arbitrary web script or HTML via the addressname parameter, also known as "Full Name".
Recommendations For IceWarp Web Mail version 3.3.3, update to a version that fixes this issue. For IceWarp Web Mail version 3.4.5, update to a version that fixes this issue. As a temporary workaround, consider restricting the use of the addressname parameter until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1899

Affected Products

Icewarp Web Mail