CVE-2007-2825: XSS
Published May 22, 2007
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in ReadMsg.php in @Mail 5.02 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) links and (2) images.
Affected Software
1 affected component
Atmail Atmail Webmail<=5.02
Remediation
Patch Available
Event History
May 22, 2007
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2825?
The severity of CVE-2007-2825 is considered moderate due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2007-2825?
To fix CVE-2007-2825, upgrade to a version of @Mail that is greater than 5.02 or apply patches if available.
3
What software is affected by CVE-2007-2825?
CVE-2007-2825 affects @Mail version 5.02 and earlier.
4
What types of attacks are possible with CVE-2007-2825?
CVE-2007-2825 allows remote attackers to perform cross-site scripting attacks through links and images.
5
Is CVE-2007-2825 a serious vulnerability?
CVE-2007-2825 can be serious as it allows for arbitrary web script injection, which could lead to credential theft or other attacks.