PT-2005-3763 · Cj · Cjweb2Mail
Psymera
·
Published
2005-09-14
·
Updated
2016-10-18
·
CVE-2005-2901
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
CjWeb2Mail version 3.0
Description
The issue allows remote attackers to inject arbitrary web script or HTML via specific parameters, including the
name, message, or ip parameter to 'thankyou.php' or the emsg parameter to 'web2mail.php'.Recommendations
For CjWeb2Mail version 3.0, consider validating and sanitizing user input for the
name, message, ip, and emsg parameters to prevent arbitrary web script or HTML injection. As a temporary workaround, restrict access to 'thankyou.php' and 'web2mail.php' to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cjweb2Mail