CVE-2012-2588
MailEnable Enterprise 6.5 - Cross-Site Scripting via Email Headers or Body
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-2588. PoCs published by loneferret.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in MailEnable Enterprise 6.5 by sending an email with a malicious payload in the Subject field. The payload executes when the victim views the email in a vulnerable client.
Description
Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Enterprise 6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, or (3) Subject header or (4) body in an SMTP e-mail message.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in MailEnable Enterprise 6.5 by sending an email with a malicious payload in the Subject field. The payload executes when the victim views the email in a vulnerable client.