4.3
CVE-2004-2334
- EPSS 4.78%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:09:27
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple cross-site scripting (XSS) vulnerabilities in EMU Webmail 5.2.7 allow remote attackers to inject arbitrary web script or HTML via (1) a hex-encoded value to the variable parameter in emumail.fcgi, (2) the folder parameter in emumail.fcgi, or Javascript in the (3) username or (4) password field in the login page.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Emumail ≫ Emu Webmail Version5.2.7
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.78% | 0.908 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
http://members.lycos.co.uk/r34ct/main/emu/emu.txt
http://secunia.com/advisories/11110
http://securitytracker.com/id?1009397
http://www.osvdb.org/4204
http://www.osvdb.org/4972
http://www.securityfocus.com/bid/9861
http://www.zone-h.com/advisories/read/id=4141
https://exchange.xforce.ibmcloud.com/vulnerabilities/15451
https://exchange.xforce.ibmcloud.com/vulnerabilities/15452