Cross-site scripting (XSS) vulnerability in search.pl in @Mail 4.61 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Atmail_webmail | Atmail | 4.3 (including) | 4.3 (including) |
Atmail_webmail | Atmail | 4.6 (including) | 4.6 (including) |
Atmail_webmail | Atmail | 4.11 (including) | 4.11 (including) |
Atmail_webmail | Atmail | 4.51 (including) | 4.51 (including) |
Atmail_webmail | Atmail | 4.61 (including) | 4.61 (including) |