CVE
- Id
- 28403
- CVE No.
- CVE-2007-5046
- Status
- Candidate
- Description
- Cross-site scripting (XSS) vulnerability in the Webmail interface for IceWarp Merak Mail Server before 9.0.0 allows remote attackers to inject arbitrary JavaScript via a javascript: URI in an attribute of an element in an email message body, as demonstrated by the onload attribute in a BODY element.
- Phase
- Assigned (20070923)
- Votes
- None (candidate not yet proposed)
- Comments