Rockliffe MailSite Express Message Body HTML Injection Vulnerability
BID:15229
Info
Rockliffe MailSite Express Message Body HTML Injection Vulnerability
| Bugtraq ID: | 15229 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 07 2005 12:00AM |
| Updated: | Jun 07 2005 12:00AM |
| Credit: | Paul Craig of Security-Assessment.com is credited with the discovery of this vulnerability. |
| Vulnerable: |
Rockliffe MailSite Express 6.1.20 |
| Not Vulnerable: |
Rockliffe MailSite Express 6.1.22 |
Discussion
Rockliffe MailSite Express Message Body HTML Injection Vulnerability
MailSite Express is prone to an HTML injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials; other attacks are also possible.
MailSite Express is prone to an HTML injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials; other attacks are also possible.
Exploit / POC
Rockliffe MailSite Express Message Body HTML Injection Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Rockliffe MailSite Express Message Body HTML Injection Vulnerability
Solution:
The vendor has addressed this issue in MailSite Express version 6.1.22. Users are advised to contact the vendor for more information on obtaining updates.
Solution:
The vendor has addressed this issue in MailSite Express version 6.1.22. Users are advised to contact the vendor for more information on obtaining updates.
References
Rockliffe MailSite Express Message Body HTML Injection Vulnerability
References:
References:
- MailSite Express Homepage (Rockliffe)
- Multiple vulnerabilities within RockLiffe MailSite Express WebMail ("Paul Craig"
)