PT-2002-2906 · Mojo Mail · Mojo Mail
Published
2002-12-31
·
Updated
2008-09-05
·
CVE-2002-2193
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Mojo Mail version 2.7
Description:
A cross-site scripting issue exists, allowing remote attackers to inject arbitrary web script via the
email parameter in mojo.cgi.Recommendations:
For Mojo Mail version 2.7, consider restricting access to the mojo.cgi script until a patch is available, and avoid using the
email parameter in vulnerable configurations to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mojo Mail