Multiple cross-site scripting (XSS) vulnerabilities in @Mail 3.64 for Windows allow remote attackers to inject arbitrary web script or HTML via (1) the Displayed Name attribute in util.pl and (2) the Folder attribute in showmail.pl.
Link | Tags |
---|---|
http://members.lycos.co.uk/r34ct/main/%40mail_3.64/%40mail_3.64.txt | |
http://www.osvdb.org/4067 | vdb entry |
http://secunia.com/advisories/10978 | third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15324 | vdb entry |
http://www.securitytracker.com/alerts/2004/Feb/1009208.html | vdb entry exploit |
http://www.osvdb.org/4066 | vdb entry |
http://www.securityfocus.com/bid/9748 | vdb entry |