CVE-2007-0953
Published Feb 15, 2007
Last updated 7 years ago
Overview
- Description
- Cross-site scripting (XSS) vulnerability in search.pl in @Mail 4.61 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:atmail:atmail_webmail:4.3:*:windows:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "38169CA6-AF64-4AA4-BB34-E3D1403991C0" }, { "criteria": "cpe:2.3:a:atmail:atmail_webmail:4.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6F8F9CAC-DA76-4C95-96DB-90F6586DE8D3" }, { "criteria": "cpe:2.3:a:atmail:atmail_webmail:4.11:*:freebsd:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A64B98C9-819A-4FF9-A456-7F83B31803EB" }, { "criteria": "cpe:2.3:a:atmail:atmail_webmail:4.11:*:hp-ux:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CE327242-FF94-4CDC-AB76-45A9A0F48478" }, { "criteria": "cpe:2.3:a:atmail:atmail_webmail:4.11:*:linux:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6CA2CC2F-0B5C-40D8-A08F-4890C15CB916" }, { "criteria": "cpe:2.3:a:atmail:atmail_webmail:4.11:*:mac_os_x:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0C041DDD-088E-464F-8AD3-228CDFF93EF7" }, { "criteria": "cpe:2.3:a:atmail:atmail_webmail:4.11:*:solaris:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4F814AB8-AD9C-4EFE-AFCD-4EB3CD742441" }, { "criteria": "cpe:2.3:a:atmail:atmail_webmail:4.51:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "83F78C65-30EE-4A96-8FA0-A280D9EA6B60" }, { "criteria": "cpe:2.3:a:atmail:atmail_webmail:4.61:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C0841FD9-F15E-43A9-B568-B21E01CC5AA2" } ], "operator": "OR" } ] } ]