CVE-2012-2586 Information
Description
Multiple cross-site scripting (XSS) vulnerabilities in Mailtraq 2.17.3.3150 allow remote attackers to inject arbitrary web script or HTML via an e-mail message subject with (1) a JavaScript alert function used in conjunction with the fromCharCode method or (2) a SCRIPT element; an e-mail message body with (3) a crafted SRC attribute of an IFRAME element (4) a data: URL in the CONTENT attribute of an HTTP-EQUIV=\refresh\ META element or (5) a Cascading Style Sheets (CSS) expression property in the STYLE attribute of an IMG element; or an e-mail message Date header with (6) a JavaScript alert function used in conjunction with the fromCharCode method (7) a SCRIPT element (8) a CSS expression property in the STYLE attribute of an arbitrary element (9) a crafted SRC attribute of an IFRAME element or (10) a data: URL in the CONTENT attribute of an HTTP-EQUIV=\refresh\ META element.
Reference
http://www.exploit-db.com/exploits/20353/
Share on: