CVE-2005-3131: XSS
Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to blank.html, or the createdataCX parameter to (2) calendard.html, (3) calendarm.html, or (4) calendarw.html.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3131?
CVE-2005-3131 is considered a medium severity vulnerability due to its potential for remote code execution through cross-site scripting.
How do I fix CVE-2005-3131?
To fix CVE-2005-3131, upgrade to the latest versions of Merak Mail Server or IceWarp Web Mail that have addressed these vulnerabilities.
What are the affected versions in CVE-2005-3131?
CVE-2005-3131 affects Merak Mail Server version 8.2.4r and IceWarp Web Mail version 5.5.1, and possibly earlier versions.
What types of attacks could exploit CVE-2005-3131?
CVE-2005-3131 can be exploited through cross-site scripting attacks, allowing the injection of arbitrary web script or HTML.
Which parameters are vulnerable in CVE-2005-3131?
The vulnerable parameters in CVE-2005-3131 include 'id' in blank.html and 'createdataCX' in calendar_d.html.