The "/cgi-bin/go" page in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via ACTION parameter without authentication. The code can executed for any user accessing the page. This vulnerability affects many mail system of governments, organizations, companies and universities.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: twcert
Published: 2019-11-20T04:06:20.948847Z
Updated: 2024-09-17T00:10:30.678Z
Reserved: 2019-08-15T00:00:00
Link: CVE-2019-15071
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-11-20T04:15:10.583
Modified: 2024-11-21T04:27:59.610
Link: CVE-2019-15071
Redhat
No data.