CVE-2011-4540 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in AtMail Open (aka AtMail Open-Source edition) 1.04 allow remote attackers to inject arbitrary web script or HTML via the func parameter to (1) ldap.php or (2) search.php.

Reference

http://osvdb.org/77330 http://secunia.com/advisories/47012 http://secunia.com/advisories/48308 http://www.securityfocus.com/bid/50792 http://www.securityfocus.com/bid/50877 https://www.dognaedis.com/vulns/DGS-SEC-1.html

Share on: