Open WebMail Openwebmail-read.PL Cross-Site Scripting Vulnerability
BID:18598
CVE-2006-3233 |Info
Open WebMail Openwebmail-read.PL Cross-Site Scripting Vulnerability
| Bugtraq ID: | 18598 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-3229 CVE-2006-3233 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 22 2006 12:00AM |
| Updated: | Jul 05 2016 09:38PM |
| Credit: | This issue was disclosed by the vendor. |
| Vulnerable: |
Open Webmail Open Webmail 2.51 Open Webmail Open Webmail 2.41 Open Webmail Open Webmail 2.32 Open Webmail Open Webmail 2.31 Open Webmail Open Webmail 2.30 Open Webmail Open Webmail 2.21 Open Webmail Open Webmail 2.20 Open Webmail Open Webmail 2.5 Open Webmail Open Webmail 1.90 Open Webmail Open Webmail 1.81 Open Webmail Open Webmail 1.71 Open Webmail Open Webmail 1.8 Open Webmail Open Webmail 1.7 Frank McIngvale LuxMan 1.7.1 |
| Not Vulnerable: |
Open Webmail Open Webmail -current |
Discussion
Open WebMail Openwebmail-read.PL Cross-Site Scripting Vulnerability
Open WebMail is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Open WebMail is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
Open WebMail Openwebmail-read.PL Cross-Site Scripting Vulnerability
Attackers can exploit this issue by enticing a victim user into following a malicious URI.
Attackers can exploit this issue by enticing a victim user into following a malicious URI.
Solution / Fix
Open WebMail Openwebmail-read.PL Cross-Site Scripting Vulnerability
Solution:
The vendor has addressed this issue in the latest SVN repository. Contact the vendor for details on obtaining the appropriate updates.
Solution:
The vendor has addressed this issue in the latest SVN repository. Contact the vendor for details on obtaining the appropriate updates.
References
Open WebMail Openwebmail-read.PL Cross-Site Scripting Vulnerability
References:
References:
- Open Webmail Homepage (Open Webmail)
- Product Changelog (Open WebMail)
- Vulnerability Summary CVE-2006-3229 (National Vulnerability Database)