CVE-2003-0130
Ximian Evolution Mail User Agent <1.2.2 - XSS
Title source: llmDescription
The handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier does not properly escape HTML characters, which allows remote attackers to inject arbitrary data and HTML via a MIME Content-ID header in a MIME-encoded image.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Core Security · textremotelinux
https://www.exploit-db.com/exploits/22371
References (9)
Scores
EPSS
0.1355
EPSS Percentile
94.1%
Classification
Status
draft
Affected Products (10)
ximian/evolution
ximian/evolution
ximian/evolution
ximian/evolution
ximian/evolution
ximian/evolution
ximian/evolution
ximian/evolution
ximian/evolution
ximian/evolution
Timeline
Published
Mar 24, 2003
Tracked Since
Feb 18, 2026