4.3

CVE-2007-0651

Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Professional before 2.37 allow remote attackers to inject arbitrary Javascript script via (1) e-mail messages and (2) the ID parameter to (a) right.asp, (b) Forms/MAI/list.asp, and (c) Forms/VCF/list.asp in mewebmail/base/default/lang/EN/.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MailenableMailenable Professional Version1.0.004
MailenableMailenable Professional Version1.0.005
MailenableMailenable Professional Version1.0.006
MailenableMailenable Professional Version1.0.007
MailenableMailenable Professional Version1.0.008
MailenableMailenable Professional Version1.0.009
MailenableMailenable Professional Version1.0.010
MailenableMailenable Professional Version1.0.011
MailenableMailenable Professional Version1.0.012
MailenableMailenable Professional Version1.0.013
MailenableMailenable Professional Version1.0.014
MailenableMailenable Professional Version1.0.015
MailenableMailenable Professional Version1.0.016
MailenableMailenable Professional Version1.0.017
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.01% 0.856
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://osvdb.org/33188
http://osvdb.org/33189
http://osvdb.org/33190
http://secunia.com/advisories/23998
Patch
Vendor Advisory
http://secunia.com/secunia_research/2007-38/advisory/
Patch
Vendor Advisory
http://securityreason.com/securityalert/2258
http://www.mailenable.com/Professional20-ReleaseNotes.txt
http://www.securityfocus.com/archive/1/460063/100/0/threaded
http://www.securityfocus.com/bid/22554
http://www.vupen.com/english/advisories/2007/0595
https://exchange.xforce.ibmcloud.com/vulnerabilities/32476
https://exchange.xforce.ibmcloud.com/vulnerabilities/32480