CVE-2005-0445: XSS
Published Feb 15, 2005
·Updated
Cross-site scripting (XSS) vulnerability in Open WebMail 2.x allows remote attackers to inject arbitrary HTML or web script via the domain name parameter (logindomain) in the login page.
Affected Software
10 affected components
Open Webmail Open WebMail=2.00
Open Webmail Open WebMail=2.01
Open Webmail Open WebMail=2.10
Open Webmail Open WebMail=2.20
Open Webmail Open WebMail=2.21
Open Webmail Open WebMail=2.30
Open Webmail Open WebMail=2.32
Open Webmail Open WebMail=2.40
Open Webmail Open WebMail=2.41
Open Webmail Open WebMail=2.50
Remediation
Patch Available
Event History
Feb 15, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0445?
CVE-2005-0445 has a moderate severity level due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2005-0445?
To fix CVE-2005-0445, upgrade Open WebMail to version 2.51 or later, which addresses this vulnerability.
3
What are the affected versions in CVE-2005-0445?
Open WebMail versions 2.00, 2.01, 2.10, 2.20, 2.21, 2.30, 2.32, 2.40, 2.41, and 2.50 are affected by CVE-2005-0445.
4
What type of vulnerability is CVE-2005-0445?
CVE-2005-0445 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary HTML or web scripts.
5
Can CVE-2005-0445 be exploited remotely?
Yes, CVE-2005-0445 can be exploited remotely by attackers through the login page of Open WebMail.