First published: Sat Dec 31 2005(Updated: )
Cross-site scripting (XSS) vulnerability in PHlyMail before 3.3 Beta1 allows remote attackers to inject arbitrary Javascript via unknown attack vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Phlymail | =3.02.01 | |
Phlymail | =3.02.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4666 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2005-4666, upgrade to PHlyMail version 3.3 Beta1 or later, which addresses the vulnerability.
CVE-2005-4666 affects users of PHlyMail versions 3.02.00 and 3.02.01.
Attackers can exploit CVE-2005-4666 to inject arbitrary JavaScript into web pages viewed by users.
CVE-2005-4666 was publicly disclosed in December 2005.