CVE

Id
6340  
CVE No.
CVE-2002-1958  
Status
Candidate  
Description
Cross-site scripting (XSS) vulnerability in kmMail 1.0, 1.0a, and 1.0b allows remote attackers to inject arbitrary web script or HTML via (1) javascript in onmouseover or other attributes in "safe" HTML tags such as the "b" tag, or (2) the Subject field.  
Phase
Assigned (20050629)  
Votes
None (candidate not yet proposed)  
Comments