First published: Fri Sep 02 2005(Updated: )
Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 and possibly other versions allows remote attackers to inject arbitrary web script or HTML via an HTML e-mail containing tags with strings that contain ">" or other special characters, which is not properly sanitized by SqWebMail.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Inter7 Vpopmail (vchkpw) | =5.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2769 is considered a high-severity vulnerability due to its potential for exploitation through cross-site scripting (XSS).
To fix CVE-2005-2769, upgrade to the latest version of SqWebMail that has addressed this vulnerability.
CVE-2005-2769 affects SqWebMail version 5.0.4 and possibly earlier versions.
CVE-2005-2769 enables remote attackers to perform cross-site scripting (XSS) attacks.
Yes, you can test for CVE-2005-2769 by sending an HTML email with unsanitized special characters to check for script execution.