CVE-2007-0651: XSS
Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Professional before 2.37 allow remote attackers to inject arbitrary Javascript script via (1) e-mail messages and (2) the ID parameter to (a) right.asp, (b) Forms/MAI/list.asp, and (c) Forms/VCF/list.asp in mewebmail/base/default/lang/EN/.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0651?
CVE-2007-0651 is classified as a medium severity vulnerability due to the potential for remote attackers to execute arbitrary scripts.
How do I fix CVE-2007-0651?
To mitigate CVE-2007-0651, users should upgrade their MailEnable Professional installations to version 2.37 or later.
What types of attacks are possible with CVE-2007-0651?
CVE-2007-0651 allows attackers to conduct cross-site scripting (XSS) attacks via e-mail messages or through specific ID parameters.
Which versions of MailEnable Professional are affected by CVE-2007-0651?
Versions of MailEnable Professional prior to 2.37, including 1.107, 1.14, and 2.33, are vulnerable to CVE-2007-0651.
What are the potential impacts of CVE-2007-0651?
The potential impacts of CVE-2007-0651 include unauthorized access to user sessions, theft of sensitive information, and spreading of malware.