CVE-2004-0591: XSS
Cross-site scripting (XSS) vulnerability in the printheaderuc function for SqWebMail 4.0.4 and earlier, and possibly 3.x, allows remote attackers to inject arbitrary web script or HRML via (1) e-mail headers or (2) a message with a "message/delivery-status" MIME Content-Type.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0591?
CVE-2004-0591 has a moderate severity rating due to its potential for cross-site scripting attacks.
How do I fix CVE-2004-0591?
To fix CVE-2004-0591, upgrade SqWebMail to version 4.0.5 or later.
What are the effects of CVE-2004-0591?
CVE-2004-0591 allows remote attackers to inject arbitrary web scripts or HTML into the application.
Which versions of SqWebMail are affected by CVE-2004-0591?
CVE-2004-0591 affects SqWebMail versions 4.0.4 and earlier, as well as potentially 3.x versions.
What types of inputs can exploit CVE-2004-0591?
CVE-2004-0591 can be exploited through malicious e-mail headers or messages with a 'message/delivery-status' MIME type.