CVE-2004-2765
Summary
| CVE | CVE-2004-2765 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-01-28 20:30:00 UTC |
| Updated | 2010-01-31 05:00:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via a crafted e-mail message, a different vulnerability than CVE-2005-2022 and CVE-2006-5486. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Redhat | Enterprise Linux | 2.1 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 2.1 | All | All | All |
| Application | Sun | Iplanet Messaging Server | 5.2 | All | All | All |
| Application | Sun | Iplanet Messaging Server | 5.2 | All | All | All |
| Application | Sun | One Messaging Server | 6.1 | All | All | All |
| Application | Sun | One Messaging Server | 6.1 | All | All | All |
| Operating System | Sun | Solaris | 2.6 | All | sparc | All |
| Operating System | Sun | Solaris | 8.0 | All | sparc | All |
| Operating System | Sun | Solaris | 9.0 | All | sparc | All |
| Operating System | Sun | Solaris | 9.0 | All | x86 | All |
| Operating System | Sun | Solaris | 2.6 | All | sparc | All |
| Operating System | Sun | Solaris | 8.0 | All | sparc | All |
| Operating System | Sun | Solaris | 9.0 | All | sparc | All |
| Operating System | Sun | Solaris | 9.0 | All | x86 | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 201601 | SUNALERT | sunsolve.sun.com | Patch, Vendor Advisory |
| #116568: Obsoleted by: 116568-57 Messaging Server 6.1: core patchjava.lang.NullPointerException | CONFIRM | sunsolve.sun.com | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.