Open WebMail Logindomain Parameter Cross-Site Scripting Vulnerability
BID:12547
Info
Open WebMail Logindomain Parameter Cross-Site Scripting Vulnerability
| Bugtraq ID: | 12547 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 14 2005 12:00AM |
| Updated: | Feb 14 2005 12:00AM |
| Credit: | Oriol Torrent Santiago is credited with the discovery of this issue. |
| Vulnerable: |
Open Webmail Open Webmail 2.32 Open Webmail Open Webmail 2.31 Open Webmail Open Webmail 2.30 Open Webmail Open Webmail 2.21 Open Webmail Open Webmail 2.20 Open Webmail Open Webmail 2.5 Open Webmail Open Webmail 1.90 Open Webmail Open Webmail 1.81 Open Webmail Open Webmail 1.71 Open Webmail Open Webmail 1.8 Open Webmail Open Webmail 1.7 |
| Not Vulnerable: | |
Discussion
Open WebMail Logindomain Parameter Cross-Site Scripting Vulnerability
Open WebMail is prone to a cross-site scripting vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied URI input.
The problem presents itself when malicious HTML and script code is sent to the application through the 'logindomain' parameter.
This vulnerability has been reported to exist in Open WebMail versions 2.50 20050212 and prior.
Open WebMail is prone to a cross-site scripting vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied URI input.
The problem presents itself when malicious HTML and script code is sent to the application through the 'logindomain' parameter.
This vulnerability has been reported to exist in Open WebMail versions 2.50 20050212 and prior.
Exploit / POC
Open WebMail Logindomain Parameter Cross-Site Scripting Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Open WebMail Logindomain Parameter Cross-Site Scripting Vulnerability
Solution:
The vendor has released a patch to address this issue. It is reported that Open Webmail versions subsequent to 2.50 20050212 are not vulnerable to this issue.
Open Webmail Open Webmail 2.5
Solution:
The vendor has released a patch to address this issue. It is reported that Open Webmail versions subsequent to 2.50 20050212 are not vulnerable to this issue.
Open Webmail Open Webmail 2.5
-
Open Webmail 2.5x.patch
http://turtle.ee.ncku.edu.tw/openwebmail/download/cert/patches/SA-05:0 1/2.5x.patch
References
Open WebMail Logindomain Parameter Cross-Site Scripting Vulnerability
References:
References:
- Open Webmail Homepage (Open Webmail)