CVE-2012-0389
MailEnable < 4.26, 5.x < 5.53, 6.x < 6.03 - Cross-Site Scripting via ForgottenPassword.aspx Username Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2012-0389. PoCs published by Sajjad Pourali.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in MailEnable webmail via the 'Username' parameter in 'ForgottenPassword.aspx'. The PoC URL injects JavaScript code that triggers an alert, proving the lack of input sanitization.
Description
Cross-site scripting (XSS) vulnerability in ForgottenPassword.aspx in MailEnable Professional, Enterprise, and Premium 4.26 and earlier, 5.x before 5.53, and 6.x before 6.03 allows remote attackers to inject arbitrary web script or HTML via the Username parameter.
Exploits (2)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in MailEnable webmail via the 'Username' parameter in 'ForgottenPassword.aspx'. The PoC URL injects JavaScript code that triggers an alert, proving the lack of input sanitization.
The provided text describes a cross-site scripting (XSS) vulnerability in MailEnable due to improper input sanitization. It includes affected versions and a sample exploit URL but lacks actual exploit code.