Back to search
CVE-2012-0389
Published: Jan 24, 2012
Modified: Aug 6, 2024
PUBLISHED
Description
Cross-site scripting (XSS) vulnerability in ForgottenPassword.aspx in MailEnable Professional, Enterprise, and Premium 4.26 and earlier, 5.x before 5.53, and 6.x before 6.03 allows remote attackers to inject arbitrary web script or HTML via the Username parameter.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
47518
third-party-advisory
x_refsource_SECUNIA
1026519
vdb-entry
x_refsource_SECTRACK
51401
vdb-entry
x_refsource_BID
20120112 ME020567: MailEnable webmail cross-site scripting vulnerability CVE-2012-0389
mailing-list
x_refsource_BUGTRAQ
78242
vdb-entry
x_refsource_OSVDB
http://www.nerv.fi/CVE-2012-0389.txt
x_refsource_MISC
http://www.mailenable.com/kb/Content/Article.asp?ID=me020567
x_refsource_CONFIRM
mailenable-forgottenpassword-xss(72380)
vdb-entry
x_refsource_XF
47562
third-party-advisory
x_refsource_SECUNIA
18447
exploit
x_refsource_EXPLOIT-DB
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now