First published: Tue Dec 31 2002(Updated: )
Cross-site scripting (XSS) vulnerability in IceWarp Web Mail 3.3.3 and 3.4.5 allows remote attackers to inject arbitrary web script or HTML via the "Full Name" (addressname) parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IceWarp WebMail Server | =3.3.3 | |
IceWarp WebMail Server | =3.3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1899 is classified as a medium severity cross-site scripting vulnerability.
To fix CVE-2002-1899, update IceWarp Web Mail to a version that is not vulnerable, specifically beyond 3.4.5.
CVE-2002-1899 affects IceWarp Web Mail versions 3.3.3 and 3.4.5.
CVE-2002-1899 is a cross-site scripting (XSS) vulnerability.
Attackers exploiting CVE-2002-1899 can inject arbitrary web scripts or HTML into user sessions.