Vulnerability Name: | CVE-2007-2718 (CCN-34266) | ||||||||
Assigned: | 2007-05-12 | ||||||||
Published: | 2007-05-12 | ||||||||
Updated: | 2021-07-23 | ||||||||
Summary: | Cross-site scripting (XSS) vulnerability in the WebMail system in Stalker CommuniGate Pro 5.1.8 and earlier, when using Microsoft Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via crafted STYLE tags. | ||||||||
CVSS v3 Severity: | 4.8 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.5 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Sat May 12 2007 - 16:00:25 CDT CommuniGate Pro web mail persistent cross-site scripting vulnerability Source: MITRE Type: CNA CVE-2007-2718 Source: FULLDISC Type: UNKNOWN 20070512 CommuniGate Pro web mail persistent cross-site scripting vulnerability Source: OSVDB Type: UNKNOWN 36017 Source: CCN Type: SA25250 CommuniGate Pro WebMail Script Insertion Vulnerability Source: SECUNIA Type: Patch, Vendor Advisory 25250 Source: CCN Type: SECTRACK ID: 1018048 CommuniGate Pro Input Validation Hole in Style Tags Permits Cross-Site Scripting Attacks Source: MISC Type: UNKNOWN http://www.communigate.com/CommuniGatePro/History51.html Source: CCN Type: OSVDB ID: 36017 CommuniGate Pro WebMail w/ MSIE STYLE Tag XSS Source: MISC Type: Vendor Advisory http://www.scanit.be/advisory-2007-05-12.html Source: BID Type: Patch 23950 Source: CCN Type: BID-23950 CommuniGate Pro Web Mail HTML Injection Vulnerability Source: SECTRACK Type: Patch 1018048 Source: CCN Type: CommuniGate Web site CommuniGate Systems Source: VUPEN Type: UNKNOWN ADV-2007-1795 Source: XF Type: UNKNOWN communigate-mail-xss(34266) Source: XF Type: UNKNOWN communigate-mail-xss(34266) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |