peter bassill · operator
$ cve CVE-2005-4209 JSON

CVE-2005-4209 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 2.1% (pctl 81)

Patch early

A public exploit exists.

Description

WorldClient webmail in Alt-N MDaemon 8.1.3 allows remote attackers to prevent arbitrary users from accessing their inboxes via script tags in the Subject header of an e-mail message, which prevents the user from being able to access the Inbox folder, possibly due to a cross-site scripting (XSS) vulnerability.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
EPSS2.13% — more likely to be exploited than 81% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2005-12-13
Last modified2026-06-16

Affected (2)

VendorProduct
alt-nmdaemon
alt-nworldclient

Public exploits

SourceTitleDate
exploit-dbAlt-N MDaemon WorldClient 8.1.3 - Denial of Service2005-12-12

References

→ the Explorer  ·  watch your stack  ·  NVD