CVE-2004-2704 describes a cross-site scripting (XSS) vulnerability in Hastymail versions 1.0.1 and earlier (stable) and 1.1 and earlier (development), specifically when used with Microsoft Internet Explorer. The flaw stems from Hastymail's failure to include the "attachment" parameter in the Content-Disposition header for attachments, causing Internet Explorer to render them inline. This misrendering allows for XSS and potentially other client-side attacks. The vulnerability has a CVSS score of 4.3 (Medium), indicating a network-based attack with medium complexity and a partial impact on integrity. Its EPSS score is 0.25149, suggesting a relatively low likelihood of exploitation compared to other CVEs. There is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. The vulnerability has received minimal community discussion or media coverage, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.1CPE matchmatch criteria | cpe:2.3:a:hastymail:hastymail:*:*:*:*:*:*:*:* | ||
<= 1.1CPE matchmatch criteria | cpe:2.3:a:hastymail:hastymail:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.