CVE-2019-15071
Summary
| CVE | CVE-2019-15071 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-20 04:15:00 UTC |
| Updated | 2019-11-22 16:15:00 UTC |
| Description | The "/cgi-bin/go" page in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via ACTION parameter without authentication. The code can executed for any user accessing the page. This vulnerability affects many mail system of governments, organizations, companies and universities. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| TWCERT/CC台灣電腦網路危機處理暨協調中心 | CONFIRM | www.twcert.org.tw | Third Party Advisory |
| www.chtsecurity.com/download/5011077112c76fb73f82d7eeb2b41b3bcd06c5037be242fec7b1... | CONFIRM | www.chtsecurity.com | Third Party Advisory |
| 程式工具 | 網擎資訊 | CONFIRM | www.openfind.com.tw | Product, Vendor Advisory |
| www.openfind.com.tw/taiwan/download/m2k/patch/Openfind_OF-ISAC-19-004.pdf | MISC | www.openfind.com.tw | |
| Openfind MAIL2000 Webmail Pre-Auth Cross-Site Scripting · GitHub | CONFIRM | gist.github.com | Third Party Advisory |
| Openfind MAIL2000 Webmail Pre-Auth Cross-Site Scripting · GitHub | CONFIRM | gist.github.com | Third Party Advisory |
| www.openfind.com.tw/taiwan/download/m2k/patch/Openfind_OF-ISAC-19-005.pdf | MISC | www.openfind.com.tw | |
| 台灣漏洞紀錄平台 Taiwan Vulnerability Note | CONFIRM | tvn.twcert.org.tw | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Tony Kuo (CHT Security), Vtim (CHT Security)
There are currently no legacy QID mappings associated with this CVE.