CVE-2004-2447
1st Class Mail Server 4.01 - Cross-Site Scripting via Mailbox Parameter
Title source: llmExploitation Summary
EIP tracks 6 public exploits for CVE-2004-2447. PoCs published by dr_insane.
AI-analyzed exploit summary The provided text describes vulnerabilities in 1st Class Mail Server version 4.01, including directory traversal and cross-site scripting (XSS). It includes a sample URL demonstrating an XSS payload but lacks executable exploit code.
Description
Cross-site scripting (XSS) vulnerability in 1st Class Mail Server 4.01 allows remote attackers to inject arbitrary web script or HTML via the Mailbox parameter to (1) viewmail.tagz, (2) the index script under /user/, (3) members.tagz, (4) general.tagz, (5) advanced.tagz, or (6) list.tagz.
Exploits (6)
The provided text describes vulnerabilities in 1st Class Mail Server version 4.01, including directory traversal and cross-site scripting (XSS). It includes a sample URL demonstrating an XSS payload but lacks executable exploit code.
The provided text describes vulnerabilities in 1st Class Mail Server version 4.01, including directory traversal and cross-site scripting (XSS). It includes a sample URL demonstrating the XSS vulnerability but lacks executable exploit code.
The provided text describes vulnerabilities in 1st Class Mail Server version 4.01, including directory traversal and cross-site scripting (XSS). It includes a sample URL demonstrating the XSS vulnerability but lacks executable exploit code.
The provided text describes vulnerabilities in 1st Class Mail Server version 4.01, including directory traversal and cross-site scripting (XSS) issues. It includes a sample URL demonstrating the XSS vulnerability but lacks executable exploit code.
The provided text describes vulnerabilities in 1st Class Mail Server version 4.01, including directory traversal and cross-site scripting (XSS). It includes a sample URL demonstrating the XSS vulnerability but lacks executable exploit code.
The provided text describes a directory traversal and cross-site scripting vulnerability in 1st Class Mail Server version 4.01. It includes a sample URL demonstrating the XSS attack vector but lacks executable exploit code.