" or other special characters, which is not properly sanitized by SqWebMail. "> ",or,other,special,characters,,which,is,not,properly sanitized,by,SqWebMail. "> SecuritySpace - CAN-2005-2769
 
 
 Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CAN-2005-2769
Description:Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 and possibly other versions allows remote attackers to inject arbitrary web script or HTML via an HTML e-mail containing tags with strings that contain ">" or other special characters, which is not properly sanitized by SqWebMail.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2005-2769
BugTraq ID: 14676
http://www.securityfocus.com/bid/14676
Bugtraq: 20050829 Secunia Research: SqWebMail HTML Emails Script Insertion (Google Search)
http://marc.info/?l=bugtraq&m=112534112715638&w=2
http://seclists.org/fulldisclosure/2005/Aug/975
http://secunia.com/secunia_research/2005-39/advisory/
http://secunia.com/advisories/16600/
http://secunia.com/advisories/17156
http://www.ubuntu.com/usn/usn-201-1
XForce ISS Database: sqwebmail-html-xss(22043)
https://exchange.xforce.ibmcloud.com/vulnerabilities/22043




© 1998-2025 E-Soft Inc. All rights reserved.