CVE-2004-2379: XSS
Multiple cross-site scripting (XSS) vulnerabilities in @Mail 3.64 for Windows allow remote attackers to inject arbitrary web script or HTML via (1) the Displayed Name attribute in util.pl and (2) the Folder attribute in showmail.pl.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2379?
CVE-2004-2379 is considered a moderate severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2004-2379?
To fix CVE-2004-2379, ensure that you update to a later version of the Atmail Webmail System that addresses these XSS vulnerabilities.
What are the main vulnerabilities in CVE-2004-2379?
CVE-2004-2379 includes multiple XSS vulnerabilities allowing remote attackers to inject arbitrary web scripts through the Displayed Name and Folder attributes.
Who is affected by CVE-2004-2379?
CVE-2004-2379 affects users of Atmail 3.64 for Windows, specifically those using the vulnerable webmail system.
Can CVE-2004-2379 be exploited remotely?
Yes, CVE-2004-2379 allows remote attackers to exploit the vulnerabilities through crafted requests.