2019-11-20 12:10:00 +08:00
{
"CVE_data_meta" : {
"ASSIGNER" : "cve@cert.org.tw" ,
"DATE_PUBLIC" : "2019-11-11T04:00:00.000Z" ,
"ID" : "CVE-2019-15072" ,
"STATE" : "PUBLIC" ,
"TITLE" : "Openfind MAIL2000 Webmail Post-Auth Cross-Site Scripting"
} ,
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"product_name" : "MAIL2000" ,
"version" : {
"version_data" : [
{
"version_affected" : "<" ,
"version_name" : "6.0" ,
"version_value" : "Before 20190919"
} ,
{
"version_affected" : "<" ,
"version_name" : "7.0" ,
"version_value" : "SP4 Patch 076"
}
]
}
}
]
} ,
"vendor_name" : "Openfind"
}
]
}
} ,
"credit" : [
{
"lang" : "eng" ,
"value" : "Tony Kuo (CHT Security), Vtim (CHT Security)"
}
] ,
"data_format" : "MITRE" ,
"data_type" : "CVE" ,
"data_version" : "4.0" ,
"description" : {
"description_data" : [
{
"lang" : "eng" ,
"value" : "The login feature in \"/cgi-bin/portal\" in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via any parameter. This vulnerability affects many mail system of governments, organizations, companies and universities."
}
]
} ,
"generator" : {
"engine" : "Vulnogram 0.0.9"
} ,
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng" ,
"value" : "CWE-79 Cross-site Scripting (XSS)"
}
]
}
]
} ,
"references" : {
"reference_data" : [
2019-11-20 05:01:19 +00:00
{
"name" : "https://www.openfind.com.tw/taiwan/resource.html" ,
"refsource" : "CONFIRM" ,
"url" : "https://www.openfind.com.tw/taiwan/resource.html"
} ,
2019-11-20 12:10:00 +08:00
{
"name" : "https://gist.github.com/chtsecurity/b3396500d4686ad47fb26f64967ef24a" ,
"refsource" : "CONFIRM" ,
"url" : "https://gist.github.com/chtsecurity/b3396500d4686ad47fb26f64967ef24a"
} ,
{
"name" : "https://gist.github.com/tonykuo76/5bf1ac369d953d5276afe0a2d04c2147" ,
"refsource" : "CONFIRM" ,
"url" : "https://gist.github.com/tonykuo76/5bf1ac369d953d5276afe0a2d04c2147"
} ,
{
"name" : "https://www.chtsecurity.com/download/0837ce00c27c73dd3ba3a0d4a7df3a41aaea1ac1e9831a5d61bb64ed484a3598.txt" ,
"refsource" : "CONFIRM" ,
"url" : "https://www.chtsecurity.com/download/0837ce00c27c73dd3ba3a0d4a7df3a41aaea1ac1e9831a5d61bb64ed484a3598.txt"
} ,
{
"name" : "https://tvn.twcert.org.tw/taiwanvn/TVN-201909002" ,
"refsource" : "CONFIRM" ,
"url" : "https://tvn.twcert.org.tw/taiwanvn/TVN-201909002"
} ,
{
"name" : "https://www.twcert.org.tw/en/cp-128-3086-ff35d-2.html" ,
"refsource" : "CONFIRM" ,
"url" : "https://www.twcert.org.tw/en/cp-128-3086-ff35d-2.html"
}
]
} ,
"source" : {
"discovery" : "EXTERNAL"
}
}