Date:
22 December 2005
Incident Type: Vulnerability Disclosure
WASC Threat Classification: Cross-site Scripting
An attacker can send an e-mail with a malicious script to a victim which is perform its actions immediately when the e-mail is read.
References: