Cross-Site Scripting Vulnerability in Sun ONE Messaging Server and iPlanet Messaging Server
CVE-2004-2765

Currently unrated

Key Information:

Vendor

Oracle

Vendor
CVE Published:
28 January 2010

What is CVE-2004-2765?

A cross-site scripting (XSS) vulnerability exists in the Webmail component of the Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 configurations prior to 5.2hf2.02. This security flaw occurs when users access the service using Internet Explorer. Attackers can exploit this vulnerability to inject arbitrary web scripts or HTML code through specially crafted email messages, potentially compromising user sessions or delivering malicious content.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.
CVE-2004-2765 : Cross-Site Scripting Vulnerability in Sun ONE Messaging Server and iPlanet Messaging Server