4.3

CVE-2007-0651

Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Professional before 2.37 allow remote attackers to inject arbitrary Javascript script via (1) e-mail messages and (2) the ID parameter to (a) right.asp, (b) Forms/MAI/list.asp, and (c) Forms/VCF/list.asp in mewebmail/base/default/lang/EN/.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MailenableMailenable Professional Version1.0.004
MailenableMailenable Professional Version1.0.005
MailenableMailenable Professional Version1.0.006
MailenableMailenable Professional Version1.0.007
MailenableMailenable Professional Version1.0.008
MailenableMailenable Professional Version1.0.009
MailenableMailenable Professional Version1.0.010
MailenableMailenable Professional Version1.0.011
MailenableMailenable Professional Version1.0.012
MailenableMailenable Professional Version1.0.013
MailenableMailenable Professional Version1.0.014
MailenableMailenable Professional Version1.0.015
MailenableMailenable Professional Version1.0.016
MailenableMailenable Professional Version1.0.017
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.77% 0.855
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.