CVE

Id
25348  
CVE No.
CVE-2007-1991  
Status
Candidate  
Description
Cross-site scripting (XSS) vulnerability in mail/signup.asp in CmailServer WebMail 5.4.3, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the Comment parameter, a different vector than CVE-2007-1927.  
Phase
Assigned (20070411)  
Votes
None (candidate not yet proposed)  
Comments