Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-4147

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2008-4147
Last Modified 17 Mar 2009 01:47:46
Published 24 Sep 2008 01:41:38
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2008-4147

Summary

Cross-site scripting (XSS) vulnerability in the Mailsave module 5.x before 5.x-3.3 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via an e-mail message with an attached file that has a modified Content-Type.

Vulnerable Systems

Application

  • Drupal Mailsave 5.x-1.0

  • Drupal Mailsave 5.x-1.x-dev

  • Drupal Mailsave 5.x-2.0

  • Drupal Mailsave 5.x-2.x-dev

  • Drupal Mailsave 5.x-3.0

  • Drupal Mailsave 5.x-3.1

  • Drupal Mailsave 5.x-3.2

  • Drupal Mailsave 5.x-3.x-dev

  • Drupal Mailsave 6.x-1.0

  • Drupal Mailsave 6.x-1.1

  • Drupal Mailsave 6.x-1.2


References

CONFIRM - http://drupal.org/node/309802

XF - mailsave-mimetype-xss(45212)

VUPEN - ADV-2008-2617

BID - 31232

SECUNIA - 31889


Last Updated: 27 May 2016 10:48:24