PT-2014-2594 · Atmail · Atmail Webmail Server
Published
2014-02-12
·
Updated
2018-10-09
·
CVE-2013-2585
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Atmail Webmail Server versions 6.6.x through 6.6.2
Atmail Webmail Server versions 7.0.x through 7.0.2
Description
A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via the PATH INFO to "index.php/mail/viewmessage/getattachment/folder/INBOX/uniqueId//filenameOriginal/".
Recommendations
For Atmail Webmail Server versions 6.6.x through 6.6.2, update to version 6.6.3 or later.
For Atmail Webmail Server versions 7.0.x through 7.0.2, update to version 7.0.3 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Atmail Webmail Server