{"api_version":"1","generated_at":"2026-07-23T04:29:17+00:00","cve":"CVE-2004-1100","urls":{"html":"https://cve.report/CVE-2004-1100","api":"https://cve.report/api/cve/CVE-2004-1100.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-1100","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-1100"},"summary":{"title":"CVE-2004-1100","description":"Cross-site scripting (XSS) vulnerability in mailpost.exe in MailPost 5.1.1sv, and possibly earlier versions, when debug mode is enabled, allows remote attackers to execute arbitrary web script or HTML via the append parameter.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-01-10 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/11596","name":"http://www.securityfocus.com/bid/11596","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"TIPS MailPost APPEND Variable Cross-Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17953","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17953","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.procheckup.com/security_info/vuln_pr0410.html","name":"http://www.procheckup.com/security_info/vuln_pr0410.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ProCheckUp - 2005","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/107998","name":"http://www.kb.cert.org/vuls/id/107998","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Vulnerability Note VU#107998","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-1100","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-1100","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"1100","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tips","cpe5":"mailpost","cpe6":"5.1.1sv","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T00:39:00.735Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.procheckup.com/security_info/vuln_pr0410.html"},{"name":"mailpost-append-xss(17953)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17953"},{"name":"VU#107998","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/107998"},{"name":"11596","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/11596"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-11-03T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in mailpost.exe in MailPost 5.1.1sv, and possibly earlier versions, when debug mode is enabled, allows remote attackers to execute arbitrary web script or HTML via the append parameter."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://www.procheckup.com/security_info/vuln_pr0410.html"},{"name":"mailpost-append-xss(17953)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17953"},{"name":"VU#107998","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/107998"},{"name":"11596","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/11596"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-1100","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in mailpost.exe in MailPost 5.1.1sv, and possibly earlier versions, when debug mode is enabled, allows remote attackers to execute arbitrary web script or HTML via the append parameter."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.procheckup.com/security_info/vuln_pr0410.html","refsource":"MISC","url":"http://www.procheckup.com/security_info/vuln_pr0410.html"},{"name":"mailpost-append-xss(17953)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17953"},{"name":"VU#107998","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/107998"},{"name":"11596","refsource":"BID","url":"http://www.securityfocus.com/bid/11596"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-1100","datePublished":"2004-12-01T05:00:00.000Z","dateReserved":"2004-11-30T00:00:00.000Z","dateUpdated":"2024-08-08T00:39:00.735Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-01-10 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:tips:mailpost:5.1.1sv:*:*:*:*:*:*:*","matchCriteriaId":"748001EF-B2A9-4E2E-80D9-235310723A93"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"1100","Ordinal":"1","Title":"CVE-2004-1100","CVE":"CVE-2004-1100","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"1100","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in mailpost.exe in MailPost 5.1.1sv, and possibly earlier versions, when debug mode is enabled, allows remote attackers to execute arbitrary web script or HTML via the append parameter.","Type":"Description","Title":"CVE-2004-1100"},{"CveYear":"2004","CveId":"1100","Ordinal":"2","NoteData":"2004-12-01","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"1100","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}