peter bassill · operator
$ cve CVE-2004-2625 JSON

CVE-2004-2625 EXPLOIT

5.1
MEDIUM · CVSS 2.0 · EPSS 2.6% (pctl 85)

Patch early

A public exploit exists.

Description

Cross-site scripting (XSS) vulnerability in Outblaze Email allows remote attackers to inject arbitrary web script or HTML via Javascript in an attribute of an IMG tag.

Scoring

CVSS5.1 (MEDIUM, v2.0)
VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
EPSS2.59% — more likely to be exploited than 85% of all CVEs
On CISA KEVno
Public exploityes
Published2004-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
outblazeoutblaze email

Public exploits

SourceTitleDate
exploit-dbOutblaze Webmail - HTML Injection2004-07-19

References

→ the Explorer  ·  watch your stack  ·  NVD