CVE-2007-5290
MailBee WebMail < 3.4 - Cross-Site Scripting via Login Mode Parameters
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2007-5290. PoCs published by Ivan Sanchez.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in MailBee WebMail Pro 3.4 and prior versions. It includes a sample URL demonstrating the vulnerability but lacks executable exploit code.
Description
Multiple cross-site scripting (XSS) vulnerabilities in MailBee WebMail Pro 3.4 and earlier; and possibly MailBee WebMail Pro ASP before 3.4.64, WebMail Lite ASP before 4.0.11, and WebMail Lite PHP before 4.0.22; allow remote attackers to inject arbitrary web script or HTML via the (1) mode parameter to login.php and the (2) mode2 parameter to default.asp in an advanced_login mode.
Exploits (2)
The provided text describes a cross-site scripting (XSS) vulnerability in MailBee WebMail Pro 3.4 and prior versions. It includes a sample URL demonstrating the vulnerability but lacks executable exploit code.
The provided text describes a cross-site scripting (XSS) vulnerability in MailBee WebMail Pro 3.4 and prior versions. It includes a sample URL demonstrating the vulnerability but lacks executable exploit code.