CVE-2004-2585: XSS
Cross-site scripting (XSS) vulnerability in frmCompose.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to inject arbitrary web script or HTML via Javascript to the "check spelling" feature in the compose area.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2585?
The severity of CVE-2004-2585 is classified as a moderate risk due to the potential for cross-site scripting attacks.
How do I fix CVE-2004-2585?
To fix CVE-2004-2585, you should upgrade to a version of SmarterMail that is not affected, preferably beyond 1.6.1529.
What type of vulnerability is CVE-2004-2585?
CVE-2004-2585 is a cross-site scripting (XSS) vulnerability allowing remote attackers to inject arbitrary web scripts.
Which versions of SmarterMail are affected by CVE-2004-2585?
CVE-2004-2585 affects SmarterMail versions 1.6.1511 and 1.6.1529.
What can attackers achieve with CVE-2004-2585?
With CVE-2004-2585, attackers can execute untrusted scripts in the context of users' sessions, compromising user data and security.