First published: Fri Sep 10 2004(Updated: )
Cross-site scripting (XSS) vulnerability in MERAK Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to execute arbitrary web script or HTML via the (1) User name parameter to accountsettings.html or (2) Search string parameter to search.html.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IceWarp WebMail Server | =3.3.2 | |
IceWarp WebMail Server | =5.2.7 | |
IceWarp WebMail Server | =5.2.8 | |
IceWarp Merak Mail Server | =7.4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1669 is classified as a high-severity cross-site scripting (XSS) vulnerability.
To fix CVE-2004-1669, upgrade to a patched version of IceWarp WebMail or Merak Mail Server that is not affected by this vulnerability.
CVE-2004-1669 affects IceWarp WebMail versions 5.2.7, 5.2.8, and Merak Mail Server version 7.4.5.
CVE-2004-1669 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML.
Attackers can exploit CVE-2004-1669 by manipulating the User name parameter or the Search string parameter to execute malicious scripts.