CVE-2009-2455: XSS
Multiple cross-site scripting (XSS) vulnerabilities in webadmin/admin.php in @mail 5.6.1 allow remote attackers to inject arbitrary web script or HTML via the (1) type and (2) func parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2455?
CVE-2009-2455 has been identified as a medium severity vulnerability due to its cross-site scripting (XSS) nature.
How do I fix CVE-2009-2455?
To fix CVE-2009-2455, upgrade to a version of Atmail higher than 5.6.1 that includes patches for XSS vulnerabilities.
What are the affected versions of Atmail for CVE-2009-2455?
CVE-2009-2455 specifically affects Atmail version 5.6.1.
What are the implications of CVE-2009-2455?
The implications of CVE-2009-2455 include potential unauthorized access to user information through the execution of malicious scripts.
How can attackers exploit CVE-2009-2455?
Attackers can exploit CVE-2009-2455 by injecting malicious scripts via the type and func parameters in webadmin/admin.php.