ArGoSoft Mail Server Pro Multiple HTML Injection Vulnerabilities
BID:16834
Info
ArGoSoft Mail Server Pro Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 16834 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 27 2006 12:00AM |
| Updated: | Mar 01 2006 03:21AM |
| Credit: | Secunia Research is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
ArGoSoft Mail Server Pro 1.8.8 .5 ArGoSoft Mail Server Pro 1.8.8 .4 ArGoSoft Mail Server Pro 1.8.8 .3 ArGoSoft Mail Server Pro 1.8.8 .1 ArGoSoft Mail Server Pro 1.8.7 .6 ArGoSoft Mail Server Pro 1.8.7 .4 ArGoSoft Mail Server Pro 1.8.7 .3 ArGoSoft Mail Server Pro 1.8.7 .1 ArGoSoft Mail Server Pro 1.8.7 .0 ArGoSoft Mail Server Pro 1.8.6 .9 ArGoSoft Mail Server Pro 1.8.6 .8 ArGoSoft Mail Server Pro 1.8.6 .7 ArGoSoft Mail Server Pro 1.8.6 .6 ArGoSoft Mail Server Pro 1.8.6 .5 ArGoSoft Mail Server Pro 1.8.6 .4 ArGoSoft Mail Server Pro 1.8.6 .3 ArGoSoft Mail Server Pro 1.8.6 .2 ArGoSoft Mail Server Pro 1.8.6 .1 ArGoSoft Mail Server Pro 1.8.1 .9 ArGoSoft Mail Server Pro 1.8.1 .8 ArGoSoft Mail Server Pro 1.8.1 .7 ArGoSoft Mail Server Pro 1.8 .1.6 ArGoSoft Mail Server Pro 1.8 .1.5 ArGoSoft Mail Server Pro 1.8.8.2 |
| Not Vulnerable: |
ArGoSoft Mail Server Pro 1.8.8 .6 |
Discussion
ArGoSoft Mail Server Pro Multiple HTML Injection Vulnerabilities
ArGoSoft Mail Server Pro is prone to multiple HTML-injection vulnerabilities. The application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
ArGoSoft Mail Server Pro 1.8.8.5 and prior versions are vulnerable.
ArGoSoft Mail Server Pro is prone to multiple HTML-injection vulnerabilities. The application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
ArGoSoft Mail Server Pro 1.8.8.5 and prior versions are vulnerable.
Exploit / POC
ArGoSoft Mail Server Pro Multiple HTML Injection Vulnerabilities
An exploit is not required.
An exploit is not required.
Solution / Fix
ArGoSoft Mail Server Pro Multiple HTML Injection Vulnerabilities
Solution:
The vendor has released version 1.8.8.6 to address these issues. Please contact the vendor to obtain fixes.
Solution:
The vendor has released version 1.8.8.6 to address these issues. Please contact the vendor to obtain fixes.
References
ArGoSoft Mail Server Pro Multiple HTML Injection Vulnerabilities
References:
References:
- ArGoSoft Mail Server Pro viewheaders Script Insertion (Secunia)
- List of Changes (ArGo Software Design)
- Mail Server Homepage (ArGoSoft)