Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail Server 5.2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) category, (2) cserver, (3) ext, (4) global, (5) showgroups, (6) or showlite parameters to address.html, or the (7) spage or (8) autoresponder parameters to settings.html, the (9) folder parameter to readmail.html, or the (10) attachmentpage_text_error parameter to attachment.html, (11) folder, (12) ct, or (13) cv parameters to calendar.html, (14) an <img> tag, or (15) the subject of an e-mail message.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Merak | Mail Server | 7.4.5 |
References
- http://marc.info/?l=bugtraq&m=109279057326044&w=2
- http://packetstormsecurity.nl/0408-exploits/merak527.txtExploitPatchVendor Advisory
- http://secunia.com/advisories/12269ExploitPatchVendor Advisory
- http://securitytracker.com/id?1010969
- http://www.osvdb.org/9037PatchVendor Advisory
- http://www.osvdb.org/9038PatchVendor Advisory
- http://www.osvdb.org/9039PatchVendor Advisory
- http://www.osvdb.org/9040PatchVendor Advisory
- http://www.osvdb.org/9041PatchVendor Advisory
- http://www.osvdb.org/9042PatchVendor Advisory
- http://www.securityfocus.com/bid/10966ExploitPatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17024
- http://marc.info/?l=bugtraq&m=109279057326044&w=2
- http://packetstormsecurity.nl/0408-exploits/merak527.txtExploitPatchVendor Advisory
- http://secunia.com/advisories/12269ExploitPatchVendor Advisory
FAQ
What is CVE-2004-1719?
CVE-2004-1719 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail Server 5.2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) category, (2) cserver, (3) ext, (4) global, ...
How severe is CVE-2004-1719?
CVE-2004-1719 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-1719?
Check the references section above for vendor advisories and patch information. Affected products include: Merak Mail Server.