SqWebMail HTML Email IMG Tag Script Injection Vulnerability
BID:14676
Info
SqWebMail HTML Email IMG Tag Script Injection Vulnerability
| Bugtraq ID: | 14676 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 29 2005 12:00AM |
| Updated: | Aug 29 2005 12:00AM |
| Credit: | Discovery is credited to Jakob Balle, Secunia Research. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 Ubuntu Ubuntu Linux 4.1 ppc Ubuntu Ubuntu Linux 4.1 ia64 Ubuntu Ubuntu Linux 4.1 ia32 Inter7 SqWebMail 5.0 .4 |
| Not Vulnerable: | |
Discussion
SqWebMail HTML Email IMG Tag Script Injection Vulnerability
SqWebMail is affected by a vulnerability that may allow remote attackers to inject and execute arbitrary script code in a user's browser.
This may allow for various attacks including session hijacking due to the theft of user credentials.
SqWebMail 5.0.4 is reportedly vulnerable to this issue. It is possible that other versions are affected as well.
SqWebMail is affected by a vulnerability that may allow remote attackers to inject and execute arbitrary script code in a user's browser.
This may allow for various attacks including session hijacking due to the theft of user credentials.
SqWebMail 5.0.4 is reportedly vulnerable to this issue. It is possible that other versions are affected as well.
Exploit / POC
SqWebMail HTML Email IMG Tag Script Injection Vulnerability
An exploit is not required.
The following proof of concept is available:
<img src="cid:>" onError="alert(document.domain);">
An exploit is not required.
The following proof of concept is available:
<img src="cid:>" onError="alert(document.domain);">
Solution / Fix
SqWebMail HTML Email IMG Tag Script Injection Vulnerability
Solution:
The latest development snapshot (26-Aug-2005) is not affected by this issue.
Ubuntu has released advisory USN-201-1 addressing this issue; please see the referenced advisory for further details.
Inter7 SqWebMail 5.0 .4
Solution:
The latest development snapshot (26-Aug-2005) is not affected by this issue.
Ubuntu has released advisory USN-201-1 addressing this issue; please see the referenced advisory for further details.
Inter7 SqWebMail 5.0 .4
-
Inter7 sqwebmail-5.0.4.20050826.tar.bz2
http://www.courier-mta.org/beta/sqwebmail/sqwebmail-5.0.4.20050826.tar .bz2
References
SqWebMail HTML Email IMG Tag Script Injection Vulnerability
References:
References:
- SqWebMail Homepage (Inter7)
- Secunia Research: SqWebMail HTML Emails Script Insertion Vulnerability (Secunia Research
)