{"api_version":"1","generated_at":"2026-07-23T09:31:56+00:00","cve":"CVE-2004-1719","urls":{"html":"https://cve.report/CVE-2004-1719","api":"https://cve.report/api/cve/CVE-2004-1719.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-1719","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-1719"},"summary":{"title":"CVE-2004-1719","description":"Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail Server 5.2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) category, (2) cserver, (3) ext, (4) global, (5) showgroups, (6) or showlite parameters to address.html, or the (7) spage or (8) autoresponder parameters to settings.html, the (9) folder parameter to readmail.html, or the (10) attachmentpage_text_error parameter to attachment.html, (11) folder, (12) ct, or (13) cv parameters to calendar.html, (14) an <img> tag, or (15) the subject of an e-mail message.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-08-17 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://packetstormsecurity.nl/0408-exploits/merak527.txt","name":"http://packetstormsecurity.nl/0408-exploits/merak527.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Vendor Advisory"],"title":"","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/10966","name":"http://www.securityfocus.com/bid/10966","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Vendor Advisory"],"title":"Merak Mail Server Webmail Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/12269","name":"http://secunia.com/advisories/12269","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Vendor Advisory"],"title":"Secunia - Advisories - IceWarp Web Mail Multiple Unspecified Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/9038","name":"http://www.osvdb.org/9038","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17024","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17024","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/9037","name":"http://www.osvdb.org/9037","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.osvdb.org/9041","name":"http://www.osvdb.org/9041","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.osvdb.org/9040","name":"http://www.osvdb.org/9040","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.osvdb.org/9039","name":"http://www.osvdb.org/9039","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.osvdb.org/9042","name":"http://www.osvdb.org/9042","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://securitytracker.com/id?1010969","name":"http://securitytracker.com/id?1010969","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Merak Mail Server Input Validation Holes Permit SQL Injection and Cross-Site Scripting Attacks - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=109279057326044&w=2","name":"http://marc.info/?l=bugtraq&m=109279057326044&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-1719","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-1719","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"1719","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"merak","cpe5":"mail_server","cpe6":"7.4.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T01:00:36.974Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://packetstormsecurity.nl/0408-exploits/merak527.txt"},{"name":"10966","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/10966"},{"name":"1010969","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1010969"},{"name":"20040817 Vulnerabilities in Merak Webmail Server","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=109279057326044&w=2"},{"name":"9040","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/9040"},{"name":"9041","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/9041"},{"name":"9037","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/9037"},{"name":"9042","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/9042"},{"name":"12269","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/12269"},{"name":"9038","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/9038"},{"name":"9039","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/9039"},{"name":"merak-xss(17024)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17024"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-08-17T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail Server 5.2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) category, (2) cserver, (3) ext, (4) global, (5) showgroups, (6) or showlite parameters to address.html, or the (7) spage or (8) autoresponder parameters to settings.html, the (9) folder parameter to readmail.html, or the (10) attachmentpage_text_error parameter to attachment.html, (11) folder, (12) ct, or (13) cv parameters to calendar.html, (14) an <img> tag, or (15) the subject of an e-mail message."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://packetstormsecurity.nl/0408-exploits/merak527.txt"},{"name":"10966","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/10966"},{"name":"1010969","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1010969"},{"name":"20040817 Vulnerabilities in Merak Webmail Server","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=109279057326044&w=2"},{"name":"9040","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/9040"},{"name":"9041","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/9041"},{"name":"9037","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/9037"},{"name":"9042","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/9042"},{"name":"12269","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/12269"},{"name":"9038","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/9038"},{"name":"9039","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/9039"},{"name":"merak-xss(17024)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17024"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-1719","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail Server 5.2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) category, (2) cserver, (3) ext, (4) global, (5) showgroups, (6) or showlite parameters to address.html, or the (7) spage or (8) autoresponder parameters to settings.html, the (9) folder parameter to readmail.html, or the (10) attachmentpage_text_error parameter to attachment.html, (11) folder, (12) ct, or (13) cv parameters to calendar.html, (14) an <img> tag, or (15) the subject of an e-mail message."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://packetstormsecurity.nl/0408-exploits/merak527.txt","refsource":"MISC","url":"http://packetstormsecurity.nl/0408-exploits/merak527.txt"},{"name":"10966","refsource":"BID","url":"http://www.securityfocus.com/bid/10966"},{"name":"1010969","refsource":"SECTRACK","url":"http://securitytracker.com/id?1010969"},{"name":"20040817 Vulnerabilities in Merak Webmail Server","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=109279057326044&w=2"},{"name":"9040","refsource":"OSVDB","url":"http://www.osvdb.org/9040"},{"name":"9041","refsource":"OSVDB","url":"http://www.osvdb.org/9041"},{"name":"9037","refsource":"OSVDB","url":"http://www.osvdb.org/9037"},{"name":"9042","refsource":"OSVDB","url":"http://www.osvdb.org/9042"},{"name":"12269","refsource":"SECUNIA","url":"http://secunia.com/advisories/12269"},{"name":"9038","refsource":"OSVDB","url":"http://www.osvdb.org/9038"},{"name":"9039","refsource":"OSVDB","url":"http://www.osvdb.org/9039"},{"name":"merak-xss(17024)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17024"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-1719","datePublished":"2005-02-26T05:00:00.000Z","dateReserved":"2005-02-26T00:00:00.000Z","dateUpdated":"2024-08-08T01:00:36.974Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-08-17 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:merak:mail_server:7.4.5:*:*:*:*:*:*:*","matchCriteriaId":"A995EEE4-9707-4FD6-9624-1168258CE0D3"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"1719","Ordinal":"1","Title":"CVE-2004-1719","CVE":"CVE-2004-1719","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"1719","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail Server 5.2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) category, (2) cserver, (3) ext, (4) global, (5) showgroups, (6) or showlite parameters to address.html, or the (7) spage or (8) autoresponder parameters to settings.html, the (9) folder parameter to readmail.html, or the (10) attachmentpage_text_error parameter to attachment.html, (11) folder, (12) ct, or (13) cv parameters to calendar.html, (14) an <img> tag, or (15) the subject of an e-mail message.","Type":"Description","Title":"CVE-2004-1719"},{"CveYear":"2004","CveId":"1719","Ordinal":"2","NoteData":"2005-02-26","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"1719","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}