Vulnonym.org

CVE-2004-2447 - Salic Hood

Description

Cross-site scripting (XSS) vulnerability in 1st Class Mail Server 4.01 allows remote attackers to inject arbitrary web script or HTML via the Mailbox parameter to (1) viewmail.tagz (2) the index script under /user/ (3) members.tagz (4) general.tagz (5) advanced.tagz or (6) list.tagz.

Reference

http://www.securityfocus.com/bid/10089 http://www.osvdb.org/5012 http://www.osvdb.org/5013 http://www.osvdb.org/5014 http://www.osvdb.org/5015 http://www.osvdb.org/5016 http://www.osvdb.org/5017 http://securitytracker.com/alerts/2004/Apr/1009705.html http://secunia.com/advisories/11330 https://exchange.xforce.ibmcloud.com/vulnerabilities/15815