CVE Database
/

CVE-2004-1101

Back to search

CVE-2004-1101

Published: Dec 1, 2004

Modified: Aug 8, 2024

PUBLISHED

Description

mailpost.exe in MailPost 5.1.1sv, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash), leak sensitive pathname information in the resulting error message, and execute a cross-site scripting (XSS) attack via an HTTP request that contains a / (backslash) and arbitrary webscript before the requested file, which leaks the pathname and does not quote the script in the resulting Visual Basic error message.

VendorProductVersions

n/a

n/a

affected
n/a

References

11598
vdb-entry
x_refsource_BID
VU#596046
third-party-advisory
x_refsource_CERT-VN
mailpost-slash-xss(17951)
vdb-entry
x_refsource_XF

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now