VulnerabilityModified
CVE-2006-5712
Cross-site scripting (XSS) vulnerability in Mirapoint WebMail allows remote attackers to inject arbitrary web script via the expression Cascading Style Sheets (CSS) function, as demonstrated using the width style for an IMG element.
MEDIUM 4.3EPSS 1.61%
Does this matter?
Lower severity and a low EPSS score (1.61%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in Mirapoint WebMail allows remote attackers to inject arbitrary web script via the expression Cascading Style Sheets (CSS) function, as demonstrated using the width style for an IMG element.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.61% probability · 75th percentile
- CISA KEV
- Not listed
- Affected
- mirapoint/mirapoint webmail
- Source
- cve@mitre.org
References
- http://marc.info/?l=full-disclosure&m=116232831525086&w=2
- http://osvdb.org/33820
- http://securitytracker.com/id?1017146Exploit
- http://www.securityfocus.com/bid/20840Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29928
- http://marc.info/?l=full-disclosure&m=116232831525086&w=2
- http://osvdb.org/33820
- http://securitytracker.com/id?1017146Exploit
- http://www.securityfocus.com/bid/20840Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29928
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.