Summary
The host is running Merak Mail Server and is prone to script injection vulnerability.
Vulnerability:
Input passed via <IMG> HTML tags in emails are not properly sanitised before being displayed in the users system.
Impact
Successful exploitation could result in insertion of arbitrary HTML and script code via a specially crafted email in a user's browser session in the context of an affected site.
Impact Level: Application
Solution
Upgrade to Merak Mail Server 9.4.0
http://www.icewarp.com
Affected
Merak Mail Server 9.3.2 and prior.
References
Severity
Classification
-
CVE CVE-2008-5734 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:P/A:N
Related Vulnerabilities