MEDIUM · 4.3

CVE-2004-2704

Hastymail 1.0.1 and earlier (stable) and 1.1 and earlier (development) does not send the "attachment" parameter in the Content-Disposition field for attachments, which causes the attachment to be rend...

Vulnerability Description

Hastymail 1.0.1 and earlier (stable) and 1.1 and earlier (development) does not send the "attachment" parameter in the Content-Disposition field for attachments, which causes the attachment to be rendered inline by Internet Explorer when the victim clicks the download link, which facilitates cross-site scripting (XSS) and possibly other attacks.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
HastymailHastymail<= 1.0.1
MicrosoftInternet ExplorerAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2004-2704?

CVE-2004-2704 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Hastymail 1.0.1 and earlier (stable) and 1.1 and earlier (development) does not send the "attachment" parameter in the Content-Disposition field for attachments, which causes the attachment to be rend...

How severe is CVE-2004-2704?

CVE-2004-2704 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-2704?

Check the references section above for vendor advisories and patch information. Affected products include: Hastymail Hastymail, Microsoft Internet Explorer.