CVE-2002-1958
Kmmail - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in kmMail 1.0, 1.0a, and 1.0b allows remote attackers to inject arbitrary web script or HTML via (1) javascript in onmouseover or other attributes in "safe" HTML tags such as the "b" tag, or (2) the Subject field.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Ulf Harnhammar · textwebappsphp
https://www.exploit-db.com/exploits/21956
References (5)
Scores
EPSS
0.0113
EPSS Percentile
78.1%
Classification
CWE
CWE-79
Status
draft
Affected Products (3)
kmmail/kmmail
kmmail/kmmail
kmmail/kmmail
Timeline
Published
Dec 31, 2002
Tracked Since
Feb 18, 2026