First published: Fri Dec 31 2004(Updated: )
Cross-site scripting (XSS) vulnerability in frmCompose.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to inject arbitrary web script or HTML via Javascript to the "check spelling" feature in the compose area.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SmarterTools SmarterMail Enterprise | =1.6.1511 | |
SmarterTools SmarterMail Enterprise | =1.6.1529 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2004-2585 is classified as a moderate risk due to the potential for cross-site scripting attacks.
To fix CVE-2004-2585, you should upgrade to a version of SmarterMail that is not affected, preferably beyond 1.6.1529.
CVE-2004-2585 is a cross-site scripting (XSS) vulnerability allowing remote attackers to inject arbitrary web scripts.
CVE-2004-2585 affects SmarterMail versions 1.6.1511 and 1.6.1529.
With CVE-2004-2585, attackers can execute untrusted scripts in the context of users' sessions, compromising user data and security.