Usermin HTML Email Script Code Execution Vulnerability
BID:10521
Info
Usermin HTML Email Script Code Execution Vulnerability
| Bugtraq ID: | 10521 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-0588 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 11 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | Disclosure of this issue is credited to Keigo Yamazaki. |
| Vulnerable: |
Usermin Usermin 1.0 70 |
| Not Vulnerable: |
Usermin Usermin 1.0 80 |
Discussion
Usermin HTML Email Script Code Execution Vulnerability
Usermin is reportedly affected by a script code execution vulnerability when rendering HTML email messages. This issue is due to a failure to sanitize HTML email messages.
This issue will allow an attacker to execute arbitrary script code in the browser of an unsuspecting user; facilitating theft of cookie based authentication credentials. This could potentially allow unauthorized access to user accounts on the computer.
Usermin is reportedly affected by a script code execution vulnerability when rendering HTML email messages. This issue is due to a failure to sanitize HTML email messages.
This issue will allow an attacker to execute arbitrary script code in the browser of an unsuspecting user; facilitating theft of cookie based authentication credentials. This could potentially allow unauthorized access to user accounts on the computer.
Exploit / POC
Usermin HTML Email Script Code Execution Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
Usermin HTML Email Script Code Execution Vulnerability
Solution:
The vendor has released an upgrade dealing with this issue.
Gentoo Linux has released advisory GLSA 200406-15 dealing with this issue. Please see the referenced advisory for further information. Users of affected packages are urged to execute the following as superuser:
emerge sync
emerge -pv ">=app-admin/usermin-1.080"
emerge ">=app-admin/usermin-1.080"
Usermin Usermin 1.0 70
Solution:
The vendor has released an upgrade dealing with this issue.
Gentoo Linux has released advisory GLSA 200406-15 dealing with this issue. Please see the referenced advisory for further information. Users of affected packages are urged to execute the following as superuser:
emerge sync
emerge -pv ">=app-admin/usermin-1.080"
emerge ">=app-admin/usermin-1.080"
Usermin Usermin 1.0 70
-
Usermin usermin-1.080.tar.gz
http://www.webmin.com/udownload.html
References
Usermin HTML Email Script Code Execution Vulnerability
References:
References: