{ "id": "CVE-2008-4045", "sourceIdentifier": "cve@mitre.org", "published": "2008-09-11T21:06:47.897", "lastModified": "2017-08-08T01:32:21.560", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "Multiple cross-site scripting (XSS) vulnerabilities in @Mail 5.42 allow remote attackers to inject arbitrary web script or HTML via the (1) file and (2) HelpFile parameters to parse.php, the (3) Folder and (4) start parameters to showmail.php, and the (5) abookview parameter to abook.php." }, { "lang": "es", "value": "Vulnerabilidad de secuencias de comandos en sitios cruzados - XSS en @Mail 5.42 que permite a los atacantes remotos inyectar arbitrariamente una secuencia de comandos web o HTML a trav\u00e9s de (1) file y (2) el par\u00e1metro HelpFile de parse.php, (3) Folder y el (4) par\u00e1metro start para showmail.php, y el par\u00e1metro (5) abookview para abook.php." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "NONE", "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "availabilityImpact": "NONE", "baseScore": 4.3 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.6, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-79" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:\\@mail:\\@mail:5.42:*:*:*:*:*:*:*", "matchCriteriaId": "B801D665-E527-4B7F-A17E-54F8715B2E28" } ] } ] } ], "references": [ { "url": "http://packetstorm.linuxsecurity.com/0808-exploits/atmail542-xss.txt", "source": "cve@mitre.org" }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44860", "source": "cve@mitre.org" } ] }