vendor:
MailEnable Enterprise
by:
loneferret
7,5
CVSS
HIGH
Cross-Site Scripting (XSS)
79
CWE
Product Name: MailEnable Enterprise
Affected Version From: 6.5
Affected Version To: 6.5
Patch Exists: YES
Related CWE: N/A
CPE: a:mailenable:mailenable_enterprise:6.5
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows Server 2003 SP2, Windows 7 Pro SP1 (x86)
2012
MailEnable Enterprise 6.5 XSS Vulnerability
MailEnable Enterprise 6.5 is vulnerable to Cross-Site Scripting (XSS) attacks. An attacker can inject malicious JavaScript code into the 'From', 'Body', 'To' and 'Subject' fields of an email message. This code will be executed when the message is viewed by the recipient. The malicious code can be used to steal cookies, hijack sessions, and redirect users to malicious websites.
Mitigation:
MailEnable Enterprise 6.5 should be upgraded to the latest version to mitigate this vulnerability.