CVE-2014-3878
IPSwitch IMail Server WEB client 12.4 - Persistent Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in the web client interface in Ipswitch IMail Server 12.3 and 12.4, possibly before 12.4.1.15, allow remote attackers to inject arbitrary web script or HTML via (1) the Name field in an add new contact action in the Contacts section or unspecified vectors in (2) an Add Group task in the Contacts section, (3) an add new event action in the Calendar section, or (4) the Task section.
Múltiples vulnerabilidades de XSS en la interfaz de cliente web en Ipswitch IMail Server 12.3 y 12.4, posiblemente anterior a 12.4.1.15, permiten a atacantes remotos inyectar secuencias de comandos web o HTML arbirarios a través de (1) el campo Name en una acción de añadir nuevo contacto en la sección Contacts o vectores no especificados en (2) una tarea Add Group en la sección Contacts, (3) una acción de añadir nuevo contacto en la sección Calendar o (4) la sección Task.
IPSwitch IMail server web client versions 12.3 and 12.4 before 12.4.1.15 suffer from a persistent cross site scripting vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-05-27 CVE Reserved
- 2014-06-03 First Exploit
- 2014-06-04 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://seclists.org/fulldisclosure/2014/Jun/19 | Mailing List | |
http://www.securityfocus.com/bid/67830 | Vdb Entry | |
http://www.securitytracker.com/id/1030335 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/33633 | 2014-06-03 | |
http://packetstormsecurity.com/files/126948/IPSwitch-IMail-12.4-Cross-Site-Scripting.html | 2024-08-06 | |
http://www.exploit-db.com/exploits/33633 | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ipswitch Search vendor "Ipswitch" | Imail Server Search vendor "Ipswitch" for product "Imail Server" | 12.3 Search vendor "Ipswitch" for product "Imail Server" and version "12.3" | - |
Affected
| ||||||
Ipswitch Search vendor "Ipswitch" | Imail Server Search vendor "Ipswitch" for product "Imail Server" | 12.4 Search vendor "Ipswitch" for product "Imail Server" and version "12.4" | - |
Affected
|