Back

CVE-2004-0591

Cross-site scripting (XSS) vulnerability in the print_header_uc function for SqWebMail 4.0.4 and earlier, and possibly 3.x, allows remote attackers to inject arbitrary web script or HRML via (1) e-mail headers or (2) a message with a "message/delivery-status" MIME Content-Type.

Published: Aug 6, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
inter7 sqwebmail 4.0.4

GitHub Security Advisory GHSA-986j-hw45-768j

Cross-site scripting (XSS) vulnerability in the print_header_uc function for SqWebMail 4.0.4 and...

Risk Scores

CVSS Score 6.8 / 10
EPSS Score 4.97%

Top 9% most likely to be exploited

Threat Score 28.7 / 100

Data Sources

NVD EPSS GitHub