Multiple cross-site scripting (XSS) vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the email, (2) cond, or (3) name parameters to (a) addressbook.view.php, (4) the daysprune parameter to (b) index.php, (5) the data[to] parameter to (c) compose.email.php, and (6) the markas parameter to (d) read.markas.php.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2006-07-13T01:00:00
Updated: 2024-08-07T18:30:34.470Z
Reserved: 2006-07-12T00:00:00
Link: CVE-2006-3564

No data.

Status : Modified
Published: 2006-07-13T01:05:00.000
Modified: 2024-11-21T00:13:54.420
Link: CVE-2006-3564

No data.