CVE-2004-2494
Ability Mail Server 1.18 - Cross-Site Scripting via erromsg Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-2494. PoCs published by dr_insane.
AI-analyzed exploit summary The provided text describes two vulnerabilities in Ability Mail Server 1.18: a cross-site scripting (XSS) vulnerability and a denial of service (DoS) vulnerability. The XSS can be triggered via a crafted URL, while the DoS requires establishing multiple connections to various services.
Description
Cross-site scripting (XSS) vulnerability in _error in Ability Mail Server 1.18 allows remote attackers to inject arbitrary web script or HTML via the erromsg parameter.
Exploits (1)
The provided text describes two vulnerabilities in Ability Mail Server 1.18: a cross-site scripting (XSS) vulnerability and a denial of service (DoS) vulnerability. The XSS can be triggered via a crafted URL, while the DoS requires establishing multiple connections to various services.