VYPR
Unrated severityNVD Advisory· Published Oct 22, 2009· Updated Jun 16, 2026

CVE-2009-3748

CVE-2009-3748

Description

Multiple cross-site scripting (XSS) vulnerabilities in the Web Administrator in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security 7.1 before Hotfix 4 allow remote attackers to inject arbitrary web script or HTML via the (1) FileName, (2) IsolatedMessageID, (3) ServerName, (4) Dictionary, (5) Scoring, and (6) MessagePart parameters to web/msgList/viewmsg/actions/msgAnalyse.asp; the (7) Queue, (8) FileName, (9) IsolatedMessageID, and (10) ServerName parameters to actions/msgForwardToRiskFilter.asp and viewHeaders.asp in web/msgList/viewmsg/; and (11) the subject in an e-mail message that is held in a Queue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:websense:personal_email_manager:7.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:websense:personal_email_manager:7.1:*:*:*:*:*:*:*
    • (no CPE)range: 7.1 before Hotfix 4
  • cpe:2.3:a:websense:websense_email_security:7.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:websense:websense_email_security:7.1:*:*:*:*:*:*:*
    • (no CPE)range: 7.1 before Hotfix 4

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.