Outblaze Webmail HTML Injection Vulnerability
BID:10756
Info
Outblaze Webmail HTML Injection Vulnerability
| Bugtraq ID: | 10756 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 19 2004 12:00AM |
| Updated: | Sep 20 2006 10:11PM |
| Credit: | DarkBicho <[email protected]> disclosed this vulnerability. |
| Vulnerable: |
Outblaze Webmail 0 |
| Not Vulnerable: | |
Discussion
Outblaze Webmail HTML Injection Vulnerability
Outblaze Webmail is reported prone to an-HTML injection vulnerability because the application fails to properly sanitize user-supplied HTML email content.
An attacker may be able to inject HTML and script code into the application through HTML email because it isn't properly sanitized.
An attacker can exploit this issue to access an unsuspecting user's cookie-based authentication credentials and to retrieve personal email. Other attacks are also possible.
Outblaze Webmail is reported prone to an-HTML injection vulnerability because the application fails to properly sanitize user-supplied HTML email content.
An attacker may be able to inject HTML and script code into the application through HTML email because it isn't properly sanitized.
An attacker can exploit this issue to access an unsuspecting user's cookie-based authentication credentials and to retrieve personal email. Other attacks are also possible.
Exploit / POC
Outblaze Webmail HTML Injection Vulnerability
No exploit is required. An example proof-of-concept HTML tag was provided:
<IMG SRC="javasc
ript:alert (document.cookie)";" border="0" height="1" width="1">
No exploit is required. An example proof-of-concept HTML tag was provided:
<IMG SRC="javasc
ript:alert (document.cookie)";" border="0" height="1" width="1">
Solution / Fix
Outblaze Webmail HTML Injection Vulnerability
Solution:
The vendor has released a fix to correct this issue. Please contact the vendor for details.
Solution:
The vendor has released a fix to correct this issue. Please contact the vendor for details.
References
Outblaze Webmail HTML Injection Vulnerability
References:
References:
- Cross-Site Scripting email Outblaze (DarkBicho)
- Outblaze HomePage (Outblaze)