First published: Thu Jan 28 2010(Updated: )
Cross-site scripting (XSS) vulnerability in Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via a crafted e-mail message, a different vulnerability than CVE-2005-2022 and CVE-2006-5486.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun iPlanet Messaging Server | =5.2 | |
Oracle Solaris SPARC | =2.6 | |
Oracle Solaris SPARC | =8.0 | |
Sun iPlanet Messaging Server | =6.1 | |
Oracle Solaris SPARC | =9.0 | |
Oracle Solaris SPARC | =9.0 | |
Red Hat Enterprise Linux | =2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2765 is classified as a medium-severity vulnerability due to its potential to allow cross-site scripting attacks.
To mitigate CVE-2004-2765, upgrade to the latest patched version of Sun ONE Messaging Server or iPlanet Messaging Server.
CVE-2004-2765 affects Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before version 5.2hf2.02.
Systems running affected versions of Sun ONE Messaging Server or iPlanet Messaging Server are at risk due to CVE-2004-2765.
CVE-2004-2765 facilitates cross-site scripting (XSS) attacks through crafted email messages.