CVE-2004-2704 Information
Feb 14, 2021
cve
Description
Hastymail 1.0.1 and earlier (stable) and 1.1 and earlier (development) does not send the \attachment\ parameter in the Content-Disposition field for attachments which causes the attachment to be rendered inline by Internet Explorer when the victim clicks the download link which facilitates cross-site scripting (XSS) and possibly other attacks.
Reference
http://archives.neohapsis.com/archives/bugtraq/2004-08/0322.html http://hastymail.sourceforge.net/security.php http://secunia.com/advisories/12358 http://securitytracker.com/id?1011054 http://www.osvdb.org/9131 http://www.securityfocus.com/bid/11022 https://exchange.xforce.ibmcloud.com/vulnerabilities/17091
Share on: