CVE-2004-2765
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD
Description
Cross-site scripting (XSS) vulnerability in Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via a crafted e-mail message, a different vulnerability than CVE-2005-2022 and CVE-2006-5486.
Affected (2)
Products: Sun: Iplanet Messaging Server, One Messaging Server
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.2 |
| Running on/with | Platform Versions |
|---|---|
Sun Solaris | Version 2.6 |
Configuration B
| Running on/with | Platform Versions |
|---|---|
Sun Solaris | Version 8.0 |
Configuration C
| Running on/with | Platform Versions |
|---|---|
Sun Solaris | Version 9.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.1 |
| Running on/with | Platform Versions |
|---|---|
Redhat Enterprise Linux | Version 2.1 |
References (4)
Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.