01642 06 11 11 Arrange Call

Arbitrary Web Script Injection in 1st Class Mail Server 4.01

CVE-2004-2447 · MEDIUM

CVE-2004-2447

Cross-site scripting (XSS) vulnerability in 1st Class Mail Server 4.01 allows remote attackers to inject arbitrary web script or HTML via the Mailbox parameter to (1) viewmail.tagz, (2) the index script under /user/, (3) members.tagz, (4) general.tagz, (5) advanced.tagz, or (6) list.tagz.

Learn more about our Web App Pen Testing.