2 results (0.027 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

Multiple cross-site scripting (XSS) vulnerabilities in Mailbird before 2.7.5.0 r allow remote attackers to execute arbitrary JavaScript in a privileged context via a crafted HTML mail message. This vulnerability is distinct from CVE-2015-4657. Múltiples vulnerabilidades de tipo cross-site scripting (XSS) en Mailbird versiones anteriores a 2.7.5.0 r, permiten a atacantes remotos ejecutar JavaScript arbitrario en un contexto privilegiado por medio de un mensaje de correo HTML diseñado. Esta vulnerabilidad es distinta del CVE-2015-4657. • https://startrekdude.github.io/mailbird.html https://www.getmailbird.com/ReleaseNotes/LatestReleaseNotes.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

Cross-site scripting (XSS) vulnerability in Mailbird 2.0.16.0 and earlier allows remote attackers to inject arbitrary web script or HTML via an e-mail message body with a crafted URL. Vulnerabilidad de XSS en Mailbird 2.0.16.0 y anteriores permite a atacantes remotos inyectar secuencias de comandos web arbitrarios o HTML a través de un cuerpo de mensaje de e-mail con una URL manipulada. • http://seclists.org/fulldisclosure/2015/May/42 http://seclists.org/fulldisclosure/2015/May/98 http://www.securityfocus.com/bid/74815 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •