CVE-2004-2766 is a session hijacking vulnerability affecting Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 prior to 5.2hf2.02, as well as various Red Hat and Sun Enterprise Linux and Solaris distributions. This vulnerability, with a CVSS score of 4.3, allows remote unauthenticated attackers to gain unspecified access to email via a crafted email message, requiring medium attack complexity but only impacting confidentiality. There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.2CPE matchmatch criteria | cpe:2.3:a:sun:iplanet_messaging_server:5.2:*:*:*:*:*:*:* | ||
6.1CPE matchmatch criteria | cpe:2.3:a:sun:one_messaging_server:6.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.