First published: Thu Feb 06 2020(Updated: )
Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote attackers to inject arbitrary web script or HTML via the Date field of an email.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Atmail Atmail | =6.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2593 is a Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4.
CVE-2012-2593 allows remote attackers to inject arbitrary web script or HTML via the Date field of an email.
CVE-2012-2593 has a severity rating of 6.1 (medium).
To fix CVE-2012-2593, update Atmail Webmail Server to a version that is not affected by the vulnerability.
You can find more information about CVE-2012-2593 at the following references: [Exploit-db](http://www.exploit-db.com/exploits/20009) and [SecurityFocus](http://www.securityfocus.com/bid/54630).