CVE-2009-4743

AfterLogic WebMail Pro <4.7.10 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in history-storage.aspx in AfterLogic WebMail Pro 4.7.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) HistoryStorageObjectName and (2) HistoryKey parameters.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Sébastien Duquette · textwebappsasp
https://www.exploit-db.com/exploits/9857
exploitdb WORKING POC VERIFIED
by Sébastien Duquette · htmlwebappsasp
https://www.exploit-db.com/exploits/33268

Scores

EPSS 0.0249
EPSS Percentile 85.1%

Classification

CWE
CWE-79
Status published

Affected Products (3)

afterlogic/webmail_pro < 4.7.10
afterlogic/webmail_pro
n/a/n/a

Timeline

Published Mar 26, 2010
Tracked Since Feb 18, 2026