CVE-2002-1958

Kmmail - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in kmMail 1.0, 1.0a, and 1.0b allows remote attackers to inject arbitrary web script or HTML via (1) javascript in onmouseover or other attributes in "safe" HTML tags such as the "b" tag, or (2) the Subject field.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Ulf Harnhammar · textwebappsphp
https://www.exploit-db.com/exploits/21956

Scores

EPSS 0.0113
EPSS Percentile 78.1%

Classification

CWE
CWE-79
Status draft

Affected Products (3)

kmmail/kmmail
kmmail/kmmail
kmmail/kmmail

Timeline

Published Dec 31, 2002
Tracked Since Feb 18, 2026