CVE-2004-1669: XSS
Cross-site scripting (XSS) vulnerability in MERAK Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to execute arbitrary web script or HTML via the (1) User name parameter to accountsettings.html or (2) Search string parameter to search.html.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1669?
CVE-2004-1669 is classified as a high-severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2004-1669?
To fix CVE-2004-1669, upgrade to a patched version of IceWarp WebMail or Merak Mail Server that is not affected by this vulnerability.
What software is affected by CVE-2004-1669?
CVE-2004-1669 affects IceWarp WebMail versions 5.2.7, 5.2.8, and Merak Mail Server version 7.4.5.
What type of vulnerability is CVE-2004-1669?
CVE-2004-1669 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML.
How can attackers exploit CVE-2004-1669?
Attackers can exploit CVE-2004-1669 by manipulating the User name parameter or the Search string parameter to execute malicious scripts.