CVE-2004-2625

Outblaze Email - Stored Cross-Site Scripting via IMG Tag Attribute

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-2625. PoCs published by DarkBicho.

AI-analyzed exploit summary This exploit demonstrates an HTML injection vulnerability in Outblaze Webmail, where user-supplied HTML email content is not properly sanitized. The provided payload is a simple XSS vector that executes JavaScript to display the user's cookies.

Description

Cross-site scripting (XSS) vulnerability in Outblaze Email allows remote attackers to inject arbitrary web script or HTML via Javascript in an attribute of an IMG tag.

Exploits (1)

exploitdb WORKING POC VERIFIED
by DarkBicho · textwebappsphp
https://www.exploit-db.com/exploits/24291

This exploit demonstrates an HTML injection vulnerability in Outblaze Webmail, where user-supplied HTML email content is not properly sanitized. The provided payload is a simple XSS vector that executes JavaScript to display the user's cookies.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Outblaze Webmail
No auth needed
Prerequisites: Victim must view the malicious HTML email
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10756
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/8104
Exploit vdb-entry x_refsource_sectrack
http://securitytracker.com/alerts/2004/Jul/1010735.html
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/12084
Various Sources x_refsource_misc
http://www.swp-zone.org/archivos/advisory-09.txt
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16788

Scores

EPSS 0.0259
EPSS Percentile 83.3%

Details

Status published
Products (1)
outblaze/outblaze_email
Published Dec 31, 2004
Tracked Since Feb 18, 2026