SqWebMail File Attachment Script Injection Vulnerability
BID:14650
Info
SqWebMail File Attachment Script Injection Vulnerability
| Bugtraq ID: | 14650 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-2724 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 24 2005 12:00AM |
| Updated: | Jul 12 2009 05:06PM |
| Credit: | Jakob Balle is credited with the discovery of this vulnerability. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 Ubuntu Ubuntu Linux 4.1 ppc Ubuntu Ubuntu Linux 4.1 ia64 Ubuntu Ubuntu Linux 4.1 ia32 Inter7 SqWebMail 5.0 .4 Inter7 SqWebMail 5.0 .1 Inter7 SqWebMail 5.0 .0 Inter7 SqWebMail 4.0.7 Inter7 SqWebMail 4.0.6 Inter7 SqWebMail 4.0.5 Inter7 SqWebMail 4.0.4 .20040524 Inter7 SqWebMail 3.6.1 Inter7 SqWebMail 3.6 .0 Inter7 SqWebMail 3.5.3 Inter7 SqWebMail 3.5.2 Inter7 SqWebMail 3.5.1 Inter7 SqWebMail 3.5 .0 Inter7 SqWebMail 3.4.1 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 |
| Not Vulnerable: | |
Discussion
SqWebMail File Attachment Script Injection Vulnerability
SqWebMail is prone to a vulnerability with regards to an email containing file attachments.
Successful exploitation will lead to the execution of malicious script code in the context of the victim's account. The attacker's malicious code will be able to perform the same functions as the victim, for example, sending and viewing email messages; other attacks may also be possible.
SqWebMail is prone to a vulnerability with regards to an email containing file attachments.
Successful exploitation will lead to the execution of malicious script code in the context of the victim's account. The attacker's malicious code will be able to perform the same functions as the victim, for example, sending and viewing email messages; other attacks may also be possible.
Exploit / POC
SqWebMail File Attachment Script Injection Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
SqWebMail File Attachment Script Injection Vulnerability
Solution:
Debian has released advisory DSA 793-1 to address this issue. Please see the referenced advisory for more information.
Ubuntu has released advisory USN-201-1 to address this issue. Please see the referenced advisory for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Debian has released advisory DSA 793-1 to address this issue. Please see the referenced advisory for more information.
Ubuntu has released advisory USN-201-1 to address this issue. Please see the referenced advisory for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
SqWebMail File Attachment Script Injection Vulnerability
References:
References:
- [courier-users] Re: [SECUNIA] Vulnerability in SqWebMail ( Sam Varshavchik
) - SqWebMail Attached File Script Insertion Vulnerability (Secunia Research)
- SqWebMail Homepage (Inter7)