CVE-2008-5734: XSS
Cross-site scripting (XSS) vulnerability in WebMail Pro in IceWarp Software Merak Mail Server 9.3.2 allows remote attackers to inject arbitrary web script or HTML via an IMG element in an HTML e-mail message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5734?
CVE-2008-5734 is classified as a cross-site scripting (XSS) vulnerability, which can lead to exploitation of user sessions or theft of sensitive information.
How do I fix CVE-2008-5734?
To fix CVE-2008-5734, upgrade to a patched version of IceWarp Merak Mail Server that addresses this vulnerability.
Can CVE-2008-5734 be exploited remotely?
Yes, CVE-2008-5734 can be exploited remotely by injecting malicious scripts via an HTML e-mail message.
Which software versions are affected by CVE-2008-5734?
CVE-2008-5734 affects IceWarp Merak Mail Server version 9.3.2.
What types of attacks can CVE-2008-5734 facilitate?
CVE-2008-5734 can facilitate attacks such as session hijacking, data theft, and redirection to malicious websites.