Sun Java System/iPlanet Messaging Server Webmail JavaScript Injection Vulnerability
BID:20708
Info
Sun Java System/iPlanet Messaging Server Webmail JavaScript Injection Vulnerability
| Bugtraq ID: | 20708 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 24 2006 12:00AM |
| Updated: | Oct 25 2006 05:28PM |
| Credit: | Seth Hall of Ohio State University is credited with the discovery of this vulnerability. |
| Vulnerable: |
Sun Java System Messaging Server 6.2 Sun Java System Messaging Server 6.1 Sun Java System Messaging Server 6.0 Sun iPlanet Messaging Server 5.2 |
| Not Vulnerable: | |
Discussion
Sun Java System/iPlanet Messaging Server Webmail JavaScript Injection Vulnerability
Sun Java Messaging Server and iPlanet Messaging Server are prone to a vulnerability that may permit the execution of arbitrary attacker-supplied JavaScript. Attackers may exploit this issue, which resides in the Webmail facility, by injecting hostile script code through emails. When such an email is read by a user of the Webmail system, attacker-supplied JavaScript could be rendered in their browser.
Sun Java Messaging Server and iPlanet Messaging Server are prone to a vulnerability that may permit the execution of arbitrary attacker-supplied JavaScript. Attackers may exploit this issue, which resides in the Webmail facility, by injecting hostile script code through emails. When such an email is read by a user of the Webmail system, attacker-supplied JavaScript could be rendered in their browser.
Exploit / POC
Sun Java System/iPlanet Messaging Server Webmail JavaScript Injection Vulnerability
An attacker can exploit this issue by sending a malicious email to a victim's Webmail account.
An attacker can exploit this issue by sending a malicious email to a victim's Webmail account.
Solution / Fix
Sun Java System/iPlanet Messaging Server Webmail JavaScript Injection Vulnerability
Solution:
Sun has released Sun Alert ID: 102479 to address this issue. Please see the referenced advisory for information on obtaining and applying fixes.
Sun Java System Messaging Server 6.0
Sun Java System Messaging Server 6.2
Sun Java System Messaging Server 6.1
Sun iPlanet Messaging Server 5.2
Solution:
Sun has released Sun Alert ID: 102479 to address this issue. Please see the referenced advisory for information on obtaining and applying fixes.
Sun Java System Messaging Server 6.0
-
Sun 118207-56
SPARC Platform
http://sunsolve.sun.com/pub-cgi/show.pl?target=patches/patch-access -
Sun 118208-56
x86 Platform
http://sunsolve.sun.com/pub-cgi/show.pl?target=patches/patch-access -
Sun 118209-56
Linux Platform
http://sunsolve.sun.com/pub-cgi/show.pl?target=patches/patch-access
Sun Java System Messaging Server 6.2
-
Sun 118207-56
SPARC Platform
http://sunsolve.sun.com/pub-cgi/show.pl?target=patches/patch-access -
Sun 118208-56
x86 Platform
http://sunsolve.sun.com/pub-cgi/show.pl?target=patches/patch-access -
Sun 118209-56
Linux Platform
http://sunsolve.sun.com/pub-cgi/show.pl?target=patches/patch-access
Sun Java System Messaging Server 6.1
-
Sun 118207-56
SPARC Platform
http://sunsolve.sun.com/pub-cgi/show.pl?target=patches/patch-access -
Sun 118208-56
x86 Platform
http://sunsolve.sun.com/pub-cgi/show.pl?target=patches/patch-access -
Sun 118209-56
Linux Platform
http://sunsolve.sun.com/pub-cgi/show.pl?target=patches/patch-access
Sun iPlanet Messaging Server 5.2
References
Sun Java System/iPlanet Messaging Server Webmail JavaScript Injection Vulnerability
References:
References: