Sun ONE/iPlanet Messaging Server Webmail MSIE HTML Injection Vulnerability

BID:13988

Info

Sun ONE/iPlanet Messaging Server Webmail MSIE HTML Injection Vulnerability

Bugtraq ID: 13988
Class: Input Validation Error
CVE:
Remote: Yes
Local: No
Published: Jun 17 2005 12:00AM
Updated: Jun 17 2005 12:00AM
Credit: This issue was announced by the vendor.
Vulnerable: Sun ONE Messaging Server 6.2
+ Sun Solaris 9_x86
+ Sun Solaris 9
+ Sun Solaris 8_sparc
+ Sun Solaris 10.0_x86
+ Sun Solaris 10
Sun iPlanet Messaging Server 5.2
Not Vulnerable:

Discussion

Sun ONE/iPlanet Messaging Server Webmail MSIE HTML Injection Vulnerability

Sun ONE/iPlanet Messaging Server Webmail is prone to an HTML injection vulnerability. This issue may allow a remote attacker to inject hostile HTML and script code into the session of a Webmail user.

Sun has stated that this issue only affects users who access Webmail with Internet Explorer. This issue appears distinct from the vulnerability described in BID 11972 "Sun ONE/iPlanet Messaging Server Webmail HTML Injection Vulnerability".

Exploit / POC

Sun ONE/iPlanet Messaging Server Webmail MSIE HTML Injection Vulnerability

There is no exploit required.

Solution / Fix

Sun ONE/iPlanet Messaging Server Webmail MSIE HTML Injection Vulnerability

Solution:
Sun has released patches to address this issue for affected platforms. Symantec was not able to locate publicly available patches therefore customers are advised to contact Sun for more information.

Sun has updated Sun Alert 101770. More patches for various affected products are available. Please see the referenced alert for more information.


Sun ONE Messaging Server 6.2
  • Sun 118207-36
    For Solaris 8, Solaris 9, Solaris 10 running on SPARC.

  • Sun 118208-36
    For Solaris 8, Solaris 9, Solaris 10 running on x86.

References

Sun ONE/iPlanet Messaging Server Webmail MSIE HTML Injection Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report