MEDIUM · 4.3

CVE-2004-2765

Cross-site scripting (XSS) vulnerability in Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02, when Internet Explorer is used, allows remote attackers to inject...

Vulnerability Description

Cross-site scripting (XSS) vulnerability in Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via a crafted e-mail message, a different vulnerability than CVE-2005-2022 and CVE-2006-5486.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
SunIplanet Messaging Server5.2
SunSolaris2.6
SunOne Messaging Server6.1
RedhatEnterprise Linux2.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2004-2765?

CVE-2004-2765 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02, when Internet Explorer is used, allows remote attackers to inject...

How severe is CVE-2004-2765?

CVE-2004-2765 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-2765?

Check the references section above for vendor advisories and patch information. Affected products include: Sun Iplanet Messaging Server, Sun Solaris, Sun One Messaging Server, Redhat Enterprise Linux.