Cross-site scripting (XSS) vulnerability in Webmail in Sun Java System Messaging Server 6.0 through 6.2 and iPlanet Messaging Server 5.2 allows remote attackers to execute arbitrary Javascript via crafted messages.
2006-10-24T22:07:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | sun | iplanet_messaging_server | 5.2 | Yes |
Application | sun | java_system_messaging_server | 6.0 | Yes |
Application | sun | java_system_messaging_server | 6.1 | Yes |
Application | sun | java_system_messaging_server | 6.2 | Yes |