First published: Fri Dec 26 2008(Updated: )
Cross-site scripting (XSS) vulnerability in WebMail Pro in IceWarp Software Merak Mail Server 9.3.2 allows remote attackers to inject arbitrary web script or HTML via an IMG element in an HTML e-mail message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IceWarp Merak Mail Server | =9.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5734 is classified as a cross-site scripting (XSS) vulnerability, which can lead to exploitation of user sessions or theft of sensitive information.
To fix CVE-2008-5734, upgrade to a patched version of IceWarp Merak Mail Server that addresses this vulnerability.
Yes, CVE-2008-5734 can be exploited remotely by injecting malicious scripts via an HTML e-mail message.
CVE-2008-5734 affects IceWarp Merak Mail Server version 9.3.2.
CVE-2008-5734 can facilitate attacks such as session hijacking, data theft, and redirection to malicious websites.