CVE-2008-0872: XSS
Published Feb 21, 2008
·Updated
Cross-site scripting (XSS) vulnerability in SmarterTools SmarterMail Enterprise 4.3 allows remote attackers to inject arbitrary web script or HTML via a STYLE attribute of an element in the Subject field of an e-mail message.
Affected Software
1 affected component
SmarterTools SmarterMail Enterprise=4.3
Event History
Feb 21, 2008
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0872?
CVE-2008-0872 is classified as a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2008-0872?
To fix CVE-2008-0872, update to a version of SmarterMail Enterprise that addresses the XSS vulnerability.
3
What version of SmarterMail Enterprise is affected by CVE-2008-0872?
SmarterMail Enterprise version 4.3 is affected by CVE-2008-0872.
4
What type of attack does CVE-2008-0872 allow?
CVE-2008-0872 allows remote attackers to inject arbitrary web script or HTML.
5
In which field of an email does CVE-2008-0872 occur?
CVE-2008-0872 occurs in the Subject field of an email message.