1 results (0.003 seconds)

CVSS: 6.1EPSS: 0%CPEs: 5EXPL: 2

14 Mar 2014 — Multiple cross-site scripting (XSS) vulnerabilities in Proxmox Mail Gateway before 3.1-5829 allow remote attackers to inject arbitrary web script or HTML via the (1) state parameter to objects/who/index.htm or (2) User email address to quarantine/spam/manage.htm. Múltiples vulnerabilidades de XSS en Proxmox Mail Gateway anterior a 3.1-5829 permiten a atacantes remotos inyectar script Web o HTML arbitrarios a través del (1) parámetro state hacia objects/who/index.htm o (2) dirección de email de usuario hacia... • http://proxmox.com/news/archive/view/listid-1-proxmox-newsletter/mailid-48-proxmox-newsletter-march-2014-proxmox-ve-3-2-released/tmpl-component • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •