4.3

CVE-2012-0389

Exploit
Cross-site scripting (XSS) vulnerability in ForgottenPassword.aspx in MailEnable Professional, Enterprise, and Premium 4.26 and earlier, 5.x before 5.53, and 6.x before 6.03 allows remote attackers to inject arbitrary web script or HTML via the Username parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MailenableMailenable Update- Editionpro Version <= 4.26
MailenableMailenable Version1.2 Editionprofessional
MailenableMailenable Version1.2a Editionprofessional
MailenableMailenable Version1.5 Editionprofessional
MailenableMailenable Version1.6 Editionprofessional
MailenableMailenable Version1.7 Editionprofessional
MailenableMailenable Version1.17 Editionprofessional
MailenableMailenable Version1.18 Editionprofessional
MailenableMailenable Version1.19 Editionprofessional
MailenableMailenable Version1.51 Editionprofessional
MailenableMailenable Version1.52 Editionprofessional
MailenableMailenable Version1.53 Editionprofessional
MailenableMailenable Version1.54 Editionprofessional
MailenableMailenable Version1.70 Editionprofessional
MailenableMailenable Version1.71 Editionprofessional
MailenableMailenable Version1.72 Editionprofessional
MailenableMailenable Version1.73 Editionprofessional
MailenableMailenable Version1.74 Editionprofessional
MailenableMailenable Version1.75 Editionprofessional
MailenableMailenable Version1.76 Editionprofessional
MailenableMailenable Version1.77 Editionprofessional
MailenableMailenable Version1.78 Editionprofessional
MailenableMailenable Version1.79 Editionprofessional
MailenableMailenable Version3.0 Update- Editionpro
MailenableMailenable Version3.01 Update- Editionpro
MailenableMailenable Version3.02 Update- Editionpro
MailenableMailenable Version3.03 Update- Editionpro
MailenableMailenable Version3.04 Update- Editionpro
MailenableMailenable Version3.5 Update- Editionpro
MailenableMailenable Version3.6 Update- Editionpro
MailenableMailenable Version3.10 Update- Editionpro
MailenableMailenable Version3.11 Update- Editionpro
MailenableMailenable Version3.12 Update- Editionpro
MailenableMailenable Version3.13 Update- Editionpro
MailenableMailenable Version3.14 Update- Editionpro
MailenableMailenable Version3.51 Update- Editionpro
MailenableMailenable Version3.52 Editionprofessional
MailenableMailenable Version3.52 Update- Editionpro
MailenableMailenable Version3.53 Update- Editionpro
MailenableMailenable Version3.61 Update- Editionpro
MailenableMailenable Version3.62 Update- Editionpro
MailenableMailenable Version3.63 Update- Editionpro
MailenableMailenable Version4.0 Update- Editionpro
MailenableMailenable Version4.1 Update- Editionpro
MailenableMailenable Version4.01 Update- Editionpro
MailenableMailenable Version4.11 Update- Editionpro
MailenableMailenable Version4.12 Update- Editionpro
MailenableMailenable Version4.13 Update- Editionpro
MailenableMailenable Version4.14 Update- Editionpro
MailenableMailenable Version4.15 Update- Editionpro
MailenableMailenable Version4.16 Update- Editionpro
MailenableMailenable Version4.17 Update- Editionpro
MailenableMailenable Version4.22 Update- Editionpro
MailenableMailenable Version4.23 Update- Editionpro
MailenableMailenable Version4.24 Update- Editionpro
MailenableMailenable Version4.25 Update- Editionpro
MailenableMailenable Update- Editionenterprise Version <= 4.26
MailenableMailenable Version1.00 Editionenterprise
MailenableMailenable Version1.1 Editionenterprise
MailenableMailenable Version1.01 Editionenterprise
MailenableMailenable Version1.02 Editionenterprise
MailenableMailenable Version1.2 Editionenterprise
MailenableMailenable Version1.03 Editionenterprise
MailenableMailenable Version1.04 Editionenterprise
MailenableMailenable Version1.21 Editionenterprise
MailenableMailenable Version1.22 Editionenterprise
MailenableMailenable Version1.23 Editionenterprise
MailenableMailenable Version1.24 Editionenterprise
MailenableMailenable Version1.25 Editionenterprise
MailenableMailenable Version1.26 Editionenterprise
MailenableMailenable Version3.0 Update- Editionenterprise
MailenableMailenable Version3.01 Update- Editionenterprise
MailenableMailenable Version3.02 Update- Editionenterprise
MailenableMailenable Version3.03 Update- Editionenterprise
MailenableMailenable Version3.04 Update- Editionenterprise
MailenableMailenable Version3.5 Update- Editionenterprise
MailenableMailenable Version3.6 Update- Editionenterprise
MailenableMailenable Version3.10 Update- Editionenterprise
MailenableMailenable Version3.11 Update- Editionenterprise
MailenableMailenable Version3.12 Update- Editionenterprise
MailenableMailenable Version3.13 Update- Editionenterprise
MailenableMailenable Version3.14 Update- Editionenterprise
MailenableMailenable Version3.51 Update- Editionenterprise
MailenableMailenable Version3.52 Editionenterprise
MailenableMailenable Version3.52 Update- Editionenterprise
MailenableMailenable Version3.53 Update- Editionenterprise
MailenableMailenable Version3.61 Update- Editionenterprise
MailenableMailenable Version3.62 Update- Editionenterprise
MailenableMailenable Version3.63 Update- Editionenterprise
MailenableMailenable Version4.0 Update- Editionenterprise
MailenableMailenable Version4.01 Update- Editionenterprise
MailenableMailenable Version4.1 Update- Editionenterprise
MailenableMailenable Version4.11 Update- Editionenterprise
MailenableMailenable Version4.12 Update- Editionenterprise
MailenableMailenable Version4.13 Update- Editionenterprise
MailenableMailenable Version4.14 Update- Editionenterprise
MailenableMailenable Version4.15 Update- Editionenterprise
MailenableMailenable Version4.16 Update- Editionenterprise
MailenableMailenable Version4.17 Update- Editionenterprise
MailenableMailenable Version4.22 Update- Editionenterprise
MailenableMailenable Version4.23 Update- Editionenterprise
MailenableMailenable Version4.24 Update- Editionenterprise
MailenableMailenable Version4.25 Update- Editionenterprise
MailenableMailenable Editionpremium Version <= 4.26
MailenableMailenable Version4.1 Editionpremium
MailenableMailenable Version4.2 Editionpremium
MailenableMailenable Version4.21 Editionpremium
MailenableMailenable Version4.22 Editionpremium
MailenableMailenable Version4.23 Editionpremium
MailenableMailenable Version4.24 Editionpremium
MailenableMailenable Version4.25 Editionpremium
MailenableMailenable Version5.0 Editionprofessional
MailenableMailenable Version5.01 Editionprofessional
MailenableMailenable Version5.02 Editionprofessional
MailenableMailenable Version5.03 Editionprofessional
MailenableMailenable Version5.04 Editionprofessional
MailenableMailenable Version5.5 Editionprofessional
MailenableMailenable Version5.05 Editionprofessional
MailenableMailenable Version5.06 Editionprofessional
MailenableMailenable Version5.07 Editionprofessional
MailenableMailenable Version5.10 Editionprofessional
MailenableMailenable Version5.11 Editionprofessional
MailenableMailenable Version5.51 Editionprofessional
MailenableMailenable Version5.52 Editionprofessional
MailenableMailenable Version5.0 Editionenterprise
MailenableMailenable Version5.01 Editionenterprise
MailenableMailenable Version5.02 Editionenterprise
MailenableMailenable Version5.03 Editionenterprise
MailenableMailenable Version5.04 Editionenterprise
MailenableMailenable Version5.5 Editionenterprise
MailenableMailenable Version5.05 Editionenterprise
MailenableMailenable Version5.06 Editionenterprise
MailenableMailenable Version5.07 Editionenterprise
MailenableMailenable Version5.10 Editionenterprise
MailenableMailenable Version5.11 Editionenterprise
MailenableMailenable Version5.51 Editionenterprise
MailenableMailenable Version5.52 Editionenterprise
MailenableMailenable Version5.0 Editionpremium
MailenableMailenable Version5.01 Editionpremium
MailenableMailenable Version5.02 Editionpremium
MailenableMailenable Version5.03 Editionpremium
MailenableMailenable Version5.04 Editionpremium
MailenableMailenable Version5.05 Editionpremium
MailenableMailenable Version5.5 Editionpremium
MailenableMailenable Version5.06 Editionpremium
MailenableMailenable Version5.07 Editionpremium
MailenableMailenable Version5.10 Editionpremium
MailenableMailenable Version5.11 Editionpremium
MailenableMailenable Version5.51 Editionpremium
MailenableMailenable Version5.52 Editionpremium
MailenableMailenable Version6.0 Editionprofessional
MailenableMailenable Version6.01 Editionprofessional
MailenableMailenable Version6.02 Editionprofessional
MailenableMailenable Version6.0 Editionenterprise
MailenableMailenable Version6.01 Editionenterprise
MailenableMailenable Version6.02 Editionenterprise
MailenableMailenable Version6.0 Editionpremium
MailenableMailenable Version6.01 Editionpremium
MailenableMailenable Version6.02 Editionpremium
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.42% 0.943
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

http://archives.neohapsis.com/archives/bugtraq/2012-01/0090.html
Exploit
http://osvdb.org/78242
http://secunia.com/advisories/47518
Vendor Advisory
http://secunia.com/advisories/47562
Vendor Advisory
http://www.exploit-db.com/exploits/18447
http://www.mailenable.com/kb/Content/Article.asp?ID=me020567
Patch
Vendor Advisory
http://www.nerv.fi/CVE-2012-0389.txt
Exploit
http://www.securityfocus.com/bid/51401
Exploit
http://www.securitytracker.com/id?1026519
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/72380