Back

CVE-2002-1307

Cross-site scripting vulnerability (XSS) in MHonArc 2.5.12 and earlier allows remote attackers to insert script or HTML via an email message with the script in a MIME header name.

Published: Nov 29, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (3)

Vendor Product Version
mhonarc mhonarc 2.4.4
mhonarc mhonarc 2.5.2
mhonarc mhonarc 2.5.12

GitHub Security Advisory GHSA-4ghg-jxgx-f5gm

Cross-site scripting vulnerability (XSS) in MHonArc 2.5.12 and earlier allows remote attackers to...

Risk Scores

CVSS Score 6.8 / 10
EPSS Score 4.02%

Top 10% most likely to be exploited

Threat Score 28.4 / 100

Data Sources

NVD EPSS GitHub