BasiliX Webmail Email Header HTML Injection Vulnerability
BID:10666
Info
BasiliX Webmail Email Header HTML Injection Vulnerability
| Bugtraq ID: | 10666 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2004 12:00AM |
| Updated: | Jul 05 2004 12:00AM |
| Credit: | Roman Medina-Heigl Hernandez <[email protected]> disclosed this issue. |
| Vulnerable: |
Basilix Webmail 1.1.1 Basilix Webmail 1.1 .0 |
| Not Vulnerable: |
Basilix Webmail 1.1.1 fix1 |
Discussion
BasiliX Webmail Email Header HTML Injection Vulnerability
BasiliX Webmail is reported to be prone to an email header HTML injection vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied email header strings.
An attacker can exploit this issue to gain access to an unsuspecting user's cookie based authentication credentials; disclosure of personal email is possible. Other attacks are also possible.
BasiliX Webmail is reported to be prone to an email header HTML injection vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied email header strings.
An attacker can exploit this issue to gain access to an unsuspecting user's cookie based authentication credentials; disclosure of personal email is possible. Other attacks are also possible.
Exploit / POC
BasiliX Webmail Email Header HTML Injection Vulnerability
No exploit is required to leverage this issue. Successful exploitation is reported to depend on the IMAP server used to parse the offending email. The following proof of concept value of 'Content-Type' has been provided:
Content-Type: application/octet-stream"<script>window.alert(document.cookie)</script>"; name=top_secret.pdf
No exploit is required to leverage this issue. Successful exploitation is reported to depend on the IMAP server used to parse the offending email. The following proof of concept value of 'Content-Type' has been provided:
Content-Type: application/octet-stream"<script>window.alert(document.cookie)</script>"; name=top_secret.pdf
Solution / Fix
BasiliX Webmail Email Header HTML Injection Vulnerability
Solution:
The vendor has released version 1.1.1_fix1 November 18, 2003 dealing with this issue. Users of affected packages are urged to upgrade.
Basilix Webmail 1.1 .0
Basilix Webmail 1.1.1
Solution:
The vendor has released version 1.1.1_fix1 November 18, 2003 dealing with this issue. Users of affected packages are urged to upgrade.
Basilix Webmail 1.1 .0
-
Basilix BasiliX-1.1.1_fix1.tar.gz
http://prdownloads.sourceforge.net/basilix/BasiliX-1.1.1_fix1.tar.gz?d ownload
Basilix Webmail 1.1.1
-
Basilix BasiliX-1.1.1_fix1.tar.gz
http://prdownloads.sourceforge.net/basilix/BasiliX-1.1.1_fix1.tar.gz?d ownload
References
BasiliX Webmail Email Header HTML Injection Vulnerability
References:
References:
- Basilix Webmail Product Page (Basilix)