Vulnerability Name: | CCN-18501 | ||||||
Published: | 2004-12-15 | ||||||
Updated: | 2004-12-15 | ||||||
Summary: | iPlanet Messaging Server is vulnerable to script injection. A remote attacker could send an email containing malicious script, which would be executed in the victim's Web browser within the security context of the hosting site, once the email is viewed via Microsoft Internet Explorer. | ||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||
CVSS v2 Severity: | 2.6 Low (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N) 2.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||
Vulnerability Consequences: | Gain Access | ||||||
References: | Source: CCN Type: Sun Alert ID: 57691 Security Vulnerability in Webmail May Allow Unprivileged Users to Execute Arbitrary Code Source: CCN Type: CIAC Information Bulletin P-068 Sun ONE/iPlanet Messaging Server Webmail Vulnerability Source: CCN Type: BID-11972 Sun ONE/iPlanet Messaging Server Webmail HTML Injection Vulnerability Source: XF Type: UNKNOWN iplanet-sun-script-injection(18501) | ||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||
BACK |