4.3

CVE-2006-2484

Exploit

Cross-site scripting (XSS) vulnerability in index.html in IceWarp WebMail 5.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the PHPSESSID parameter.

Data is provided by the National Vulnerability Database (NVD)
IcewarpWeb Mail Version1.40.00
IcewarpWeb Mail Version1.40.10
IcewarpWeb Mail Version3.1.4
IcewarpWeb Mail Version3.3.1
IcewarpWeb Mail Version3.3.2
IcewarpWeb Mail Version3.4.1
IcewarpWeb Mail Version3.4.2
IcewarpWeb Mail Version3.5.0
IcewarpWeb Mail Version3.5.1
IcewarpWeb Mail Version4.1.4
IcewarpWeb Mail Version4.1.5
IcewarpWeb Mail Version5.2.7
IcewarpWeb Mail Version5.2.8
IcewarpWeb Mail Version5.3
IcewarpWeb Mail Version5.3.1
IcewarpWeb Mail Version5.3.2
IcewarpWeb Mail Version5.4
IcewarpWeb Mail Version5.5.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.41% 0.604
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N