1 results (0.001 seconds)

CVSS: 4.3EPSS: 0%CPEs: 5EXPL: 2

Multiple cross-site scripting (XSS) vulnerabilities in Proxmox Mail Gateway before 3.1-5829 allow remote attackers to inject arbitrary web script or HTML via the (1) state parameter to objects/who/index.htm or (2) User email address to quarantine/spam/manage.htm. Múltiples vulnerabilidades de XSS en Proxmox Mail Gateway anterior a 3.1-5829 permiten a atacantes remotos inyectar script Web o HTML arbitrarios a través del (1) parámetro state hacia objects/who/index.htm o (2) dirección de email de usuario hacia quarantine/spam/manage.htm. • http://proxmox.com/news/archive/view/listid-1-proxmox-newsletter/mailid-48-proxmox-newsletter-march-2014-proxmox-ve-3-2-released/tmpl-component http://seclists.org/fulldisclosure/2014/Mar/110 http://www.securityfocus.com/bid/66169 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •