CVE-2007-5649 | SocketMail 2.2.1 lostpwd.php lost_id cross site scripting (EDB-30694 / XFDB-37382)
A vulnerability was found in SocketMail 2.2.1. It has been classified as problematic. This affects an unknown part of the file lostpwd.php. This manipulation of the argument lost_id causes cross site scripting.
This vulnerability is registered as CVE-2007-5649. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
It is recommended to apply a patch to fix this issue.