CVE-2005-0320

Icewarp Web Mail - XSS

Title source: rule
STIX 2.1

Description

Multiple cross-site scripting vulnerabilities in MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to login.html, (2) accountid parameter to accountsettings_add.html, or the (3) note, (4) title, and (5) location fields to calendar.html.

Exploits (2)

exploitdb WRITEUP VERIFIED
by ShineShadow · textwebappsphp
https://www.exploit-db.com/exploits/25068
exploitdb WRITEUP VERIFIED
by ShineShadow · textwebappsphp
https://www.exploit-db.com/exploits/25069

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/19147
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/12396
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=110693950205007&w=2

Scores

EPSS 0.0281
EPSS Percentile 86.2%

Details

Status published
Products (1)
icewarp/web_mail 5.3
Published Jan 28, 2005
Tracked Since Feb 18, 2026