{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-24T03:05:11.944","vulnerabilities":[{"cve":{"id":"CVE-2019-15071","sourceIdentifier":"twcert@cert.org.tw","published":"2019-11-20T04:15:10.583","lastModified":"2026-06-17T02:19:38.787","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"The \"/cgi-bin/go\" page in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via ACTION parameter without authentication. The code can executed for any user accessing the page. This vulnerability affects many mail system of governments, organizations, companies and universities."},{"lang":"es","value":"La página \"/cgi-bin/go\" en MAIL2000 versiones hasta 6.0 y 7.0, tiene una vulnerabilidad de tipo cross-site scripting (XSS), permitiendo una ejecución de código arbitrario por medio del parámetro ACTION sin autenticación. El código puede ser ejecutado por cualquier usuario que acceda a la página. Esta vulnerabilidad afecta a muchos sistemas de correo de gobiernos, organizaciones, empresas y universidades."}],"affected":[{"source":"twcert@cert.org.tw","affectedData":[{"vendor":"Openfind","product":"MAIL2000","versions":[{"version":"6.0","lessThan":"Before 20190919","versionType":"custom","status":"affected"},{"version":"7.0","lessThan":"SP4 Patch 076","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"twcert@cert.org.tw","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openfind:mail2000:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndIncluding":"7.0","matchCriteriaId":"8EB23C85-2651-4BE9-A172-540DA4EC3F8B"}]}]}],"references":[{"url":"https://gist.github.com/chtsecurity/21119b393640bea1d010ab9e3bee216d","source":"twcert@cert.org.tw","tags":["Third Party Advisory"]},{"url":"https://gist.github.com/tonykuo76/95638395e0c83e68dbd3db0fa0184e27","source":"twcert@cert.org.tw","tags":["Third Party Advisory"]},{"url":"https://tvn.twcert.org.tw/taiwanvn/TVN-201909001","source":"twcert@cert.org.tw","tags":["Third Party Advisory"]},{"url":"https://www.chtsecurity.com/download/5011077112c76fb73f82d7eeb2b41b3bcd06c5037be242fec7b185603ca52dc1.txt","source":"twcert@cert.org.tw","tags":["Third Party Advisory"]},{"url":"https://www.openfind.com.tw/taiwan/download/m2k/patch/Openfind_OF-ISAC-19-004.pdf","source":"twcert@cert.org.tw"},{"url":"https://www.openfind.com.tw/taiwan/download/m2k/patch/Openfind_OF-ISAC-19-005.pdf","source":"twcert@cert.org.tw"},{"url":"https://www.openfind.com.tw/taiwan/resource.html","source":"twcert@cert.org.tw","tags":["Product","Vendor Advisory"]},{"url":"https://www.twcert.org.tw/en/cp-128-3085-45bda-2.html","source":"twcert@cert.org.tw","tags":["Third Party Advisory"]},{"url":"https://gist.github.com/chtsecurity/21119b393640bea1d010ab9e3bee216d","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gist.github.com/tonykuo76/95638395e0c83e68dbd3db0fa0184e27","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://tvn.twcert.org.tw/taiwanvn/TVN-201909001","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://www.chtsecurity.com/download/5011077112c76fb73f82d7eeb2b41b3bcd06c5037be242fec7b185603ca52dc1.txt","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://www.openfind.com.tw/taiwan/download/m2k/patch/Openfind_OF-ISAC-19-004.pdf","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.openfind.com.tw/taiwan/download/m2k/patch/Openfind_OF-ISAC-19-005.pdf","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.openfind.com.tw/taiwan/resource.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product","Vendor Advisory"]},{"url":"https://www.twcert.org.tw/en/cp-128-3085-45bda-2.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}}]}