First published: Tue Oct 04 2005(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to blank.html, or the createdataCX parameter to (2) calendar_d.html, (3) calendar_m.html, or (4) calendar_w.html.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Merak Mail Server | =8.2.4r | |
IceWarp Web Mail | =5.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3131 is considered a medium severity vulnerability due to its potential for remote code execution through cross-site scripting.
To fix CVE-2005-3131, upgrade to the latest versions of Merak Mail Server or IceWarp Web Mail that have addressed these vulnerabilities.
CVE-2005-3131 affects Merak Mail Server version 8.2.4r and IceWarp Web Mail version 5.5.1, and possibly earlier versions.
CVE-2005-3131 can be exploited through cross-site scripting attacks, allowing the injection of arbitrary web script or HTML.
The vulnerable parameters in CVE-2005-3131 include 'id' in blank.html and 'createdataCX' in calendar_d.html.