{"api_version":"1","generated_at":"2026-07-23T04:31:06+00:00","cve":"CVE-2004-1669","urls":{"html":"https://cve.report/CVE-2004-1669","api":"https://cve.report/api/cve/CVE-2004-1669.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-1669","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-1669"},"summary":{"title":"CVE-2004-1669","description":"Cross-site scripting (XSS) vulnerability in MERAK Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to execute arbitrary web script or HTML via the (1) User name parameter to accountsettings.html or (2) Search string parameter to search.html.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-09-10 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17313","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17313","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/11371","name":"http://www.securityfocus.com/bid/11371","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"IceWarp Web Mail Multiple Unspecified Remote Input Validation Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://marc.info/?l=bugtraq&m=109483971420067&w=2","name":"http://marc.info/?l=bugtraq&m=109483971420067&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'Multiple vulnerabilities in Icewarp Web Mail 5.2.7' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/12789","name":"http://secunia.com/advisories/12789","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - IceWarp Web Mail Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-1669","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-1669","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"1669","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"icewarp","cpe5":"web_mail","cpe6":"3.3.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1669","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"icewarp","cpe5":"web_mail","cpe6":"5.2.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1669","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"icewarp","cpe5":"web_mail","cpe6":"5.2.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1669","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"merak","cpe5":"mail_server","cpe6":"7.4.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T01:00:37.064Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"merak-icewarp-xss(17313)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17313"},{"name":"20040910 Multiple vulnerabilities in Icewarp Web Mail 5.2.7","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=109483971420067&w=2"},{"name":"12789","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/12789"},{"name":"11371","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/11371"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-09-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in MERAK Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to execute arbitrary web script or HTML via the (1) User name parameter to accountsettings.html or (2) Search string parameter to search.html."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"merak-icewarp-xss(17313)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17313"},{"name":"20040910 Multiple vulnerabilities in Icewarp Web Mail 5.2.7","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=109483971420067&w=2"},{"name":"12789","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/12789"},{"name":"11371","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/11371"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-1669","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in MERAK Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to execute arbitrary web script or HTML via the (1) User name parameter to accountsettings.html or (2) Search string parameter to search.html."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"merak-icewarp-xss(17313)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17313"},{"name":"20040910 Multiple vulnerabilities in Icewarp Web Mail 5.2.7","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=109483971420067&w=2"},{"name":"12789","refsource":"SECUNIA","url":"http://secunia.com/advisories/12789"},{"name":"11371","refsource":"BID","url":"http://www.securityfocus.com/bid/11371"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-1669","datePublished":"2005-02-20T05:00:00.000Z","dateReserved":"2005-02-21T00:00:00.000Z","dateUpdated":"2024-08-08T01:00:37.064Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-09-10 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:icewarp:web_mail:3.3.2:*:*:*:*:*:*:*","matchCriteriaId":"59B3A55C-9EAE-4CEA-BC13-99EEEF3B456B"},{"vulnerable":true,"criteria":"cpe:2.3:a:icewarp:web_mail:5.2.7:*:*:*:*:*:*:*","matchCriteriaId":"CEFA5E8D-C505-443A-BF27-1B1B80F6AE49"},{"vulnerable":true,"criteria":"cpe:2.3:a:icewarp:web_mail:5.2.8:*:*:*:*:*:*:*","matchCriteriaId":"559FAE27-0092-4C36-9D21-4E79696B7EC1"},{"vulnerable":true,"criteria":"cpe:2.3:a:merak:mail_server:7.4.5:*:*:*:*:*:*:*","matchCriteriaId":"A995EEE4-9707-4FD6-9624-1168258CE0D3"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"1669","Ordinal":"1","Title":"CVE-2004-1669","CVE":"CVE-2004-1669","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"1669","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in MERAK Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to execute arbitrary web script or HTML via the (1) User name parameter to accountsettings.html or (2) Search string parameter to search.html.","Type":"Description","Title":"CVE-2004-1669"},{"CveYear":"2004","CveId":"1669","Ordinal":"2","NoteData":"2005-02-20","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"1669","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}