20050128 Multiple vulnerabilities in Icewarp Web Mail 5.3.0: New holesmailing list
http://marc.info/?l=bugtraq&m=110693950205007&w=2 CVE-2005-0320
IceWarp Web Mail 5.3 - login.html 'Username' Cross-Site Scripting
Record summary
CVE-2005-0320 has a selected CVSS score of 5.0; EIP currently links 2 catalogued exploits.
Description
Multiple cross-site scripting vulnerabilities in MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to login.html, (2) accountid parameter to accountsettings_add.html, or the (3) note, (4) title, and (5) location fields to calendar.html.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBIceWarp Web Mail 5.3 - login.html 'Username' Cross-Site ScriptingExploitDB exploitby ShineShadowNot analyzed1 file
ExploitDBIceWarp Web Mail 5.3 - 'accountsettings_add.html?accountid' Cross-Site ScriptingExploitDB exploitby ShineShadowNot analyzed1 file
References
412396vdb entry
http://www.securityfocus.com/bid/12396 merak-icewarp-multiple-xss(19147)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/19147 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2005-0320