VulnerabilityModified
CVE-2006-3095
Multiple cross-site scripting (XSS) vulnerabilities in iPostMX 2005 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the RETURNURL parameter in (1) userlogin.cfm and (2) account.cfm.
MEDIUM 4.3EPSS 1.34%
Does this matter?
Lower severity and a low EPSS score (1.34%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in iPostMX 2005 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the RETURNURL parameter in (1) userlogin.cfm and (2) account.cfm.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.34% probability · 70th percentile
- CISA KEV
- Not listed
- Affected
- ipostmx/ipostmx 2005
- Source
- cve@mitre.org
References
- http://pridels0.blogspot.com/2006/06/ipostmx-2005-vuln.html
- http://secunia.com/advisories/20697Vendor Advisory
- http://www.osvdb.org/26522
- http://www.osvdb.org/26523
- http://www.securityfocus.com/bid/18460
- http://www.vupen.com/english/advisories/2006/2382
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27140
- http://pridels0.blogspot.com/2006/06/ipostmx-2005-vuln.html
- http://secunia.com/advisories/20697Vendor Advisory
- http://www.osvdb.org/26522
- http://www.osvdb.org/26523
- http://www.securityfocus.com/bid/18460
- http://www.vupen.com/english/advisories/2006/2382
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27140
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.