CVE-2006-4956
Neon WebMail for Java < 5.08 - Cross-Site Scripting via Updateuser Servlet in_name Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4956. PoCs published by Tan Chew Keong.
AI-analyzed exploit summary The provided text describes multiple vulnerabilities in Neon WebMail, including XSS, SQL injection, and file upload issues. It includes a sample URL demonstrating an XSS attack via the 'in_name' parameter.
Description
Cross-site scripting (XSS) vulnerability in the updateuser servlet in Neon WebMail for Java before 5.08 allows remote attackers to inject arbitrary web script or HTML via the in_name parameter, as used by the Name field.
Exploits (1)
The provided text describes multiple vulnerabilities in Neon WebMail, including XSS, SQL injection, and file upload issues. It includes a sample URL demonstrating an XSS attack via the 'in_name' parameter.