Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2007-5046
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-5046

Description:
Cross-site scripting (XSS) vulnerability in the Webmail interface for IceWarp Merak Mail Server before 9.0.0 allows remote attackers to inject arbitrary JavaScript via a javascript: URI in an attribute of an element in an email message body, as demonstrated by the onload attribute in a BODY element.

CVE Status:
Candidate

References:

SAID
  Secunia Advisory: SA26877

OSVDB
  37428

MISC
  http://www.mwrinfosecurity.com/publications/mwri_merak-webmail-xss-advisory_2008-09-17.pdf

BID
  25708


Return to the previous page.