4.3

CVE-2005-2724

Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 allows remote attackers to inject arbitrary web script or HTML via a file attachment that is processed by the Display feature.  NOTE: the severity of this issue has been disputed by the developer.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Inter7Sqwebmail Version3.4.1
Inter7Sqwebmail Version3.5.0
Inter7Sqwebmail Version3.5.1
Inter7Sqwebmail Version3.5.2
Inter7Sqwebmail Version3.5.3
Inter7Sqwebmail Version3.6.0
Inter7Sqwebmail Version3.6.1
Inter7Sqwebmail Version4.0.4_2004-05-24
Inter7Sqwebmail Version4.0.5
Inter7Sqwebmail Version4.0.6
Inter7Sqwebmail Version4.0.7
Inter7Sqwebmail Version5.0.0
Inter7Sqwebmail Version5.0.1
Inter7Sqwebmail Version5.0.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.8% 0.719
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N