First published: Mon Aug 29 2005(Updated: )
Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 allows remote attackers to inject arbitrary web script or HTML via a file attachment that is processed by the Display feature. NOTE: the severity of this issue has been disputed by the developer.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Inter7 Vpopmail (vchkpw) | =3.4.1 | |
Inter7 Vpopmail (vchkpw) | =3.5.0 | |
Inter7 Vpopmail (vchkpw) | =3.5.1 | |
Inter7 Vpopmail (vchkpw) | =3.5.2 | |
Inter7 Vpopmail (vchkpw) | =3.5.3 | |
Inter7 Vpopmail (vchkpw) | =3.6.0 | |
Inter7 Vpopmail (vchkpw) | =3.6.1 | |
Inter7 Vpopmail (vchkpw) | =4.0.4_2004-05-24 | |
Inter7 Vpopmail (vchkpw) | =4.0.5 | |
Inter7 Vpopmail (vchkpw) | =4.0.6 | |
Inter7 Vpopmail (vchkpw) | =4.0.7 | |
Inter7 Vpopmail (vchkpw) | =5.0.0 | |
Inter7 Vpopmail (vchkpw) | =5.0.1 | |
Inter7 Vpopmail (vchkpw) | =5.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2005-2724 has been disputed by the developer, but it is classified as a cross-site scripting (XSS) vulnerability.
To fix CVE-2005-2724, you should upgrade to a secure version of SqWebMail that is not affected by this vulnerability.
CVE-2005-2724 affects SqWebMail versions 3.4.1 to 5.0.4.
Yes, CVE-2005-2724 exploits the file attachment feature of SqWebMail to inject arbitrary web scripts or HTML.
CVE-2005-2724 can lead to unauthorized access to user sessions and data through cross-site scripting attacks.