MailEnable Web Mail Client Multiple HTML Injection and Cross-Site Scripting Vulnerabilities
BID:22554
Info
MailEnable Web Mail Client Multiple HTML Injection and Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 22554 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-0651 CVE-2007-0652 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 14 2007 12:00AM |
| Updated: | Feb 14 2007 05:57PM |
| Credit: | JJ Reyes is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
MailEnable MailEnable Professional 1.116 MailEnable MailEnable Professional 1.115 MailEnable MailEnable Professional 1.114 MailEnable MailEnable Professional 1.113 MailEnable MailEnable Professional 1.112 MailEnable MailEnable Professional 1.111 MailEnable MailEnable Professional 1.110 MailEnable MailEnable Professional 1.109 MailEnable MailEnable Professional 1.108 MailEnable MailEnable Professional 1.107 MailEnable MailEnable Professional 1.106 MailEnable MailEnable Professional 1.105 MailEnable MailEnable Professional 1.104 MailEnable MailEnable Professional 1.103 MailEnable MailEnable Professional 1.102 MailEnable MailEnable Professional 1.101 MailEnable MailEnable Professional 1.54 MailEnable MailEnable Professional 1.53 MailEnable MailEnable Professional 1.52 MailEnable MailEnable Professional 1.51 MailEnable MailEnable Professional 1.19 MailEnable MailEnable Professional 1.19 MailEnable MailEnable Professional 1.18 MailEnable MailEnable Professional 1.18 MailEnable MailEnable Professional 1.17 MailEnable MailEnable Professional 1.17 MailEnable MailEnable Professional 1.16 MailEnable MailEnable Professional 1.16 MailEnable MailEnable Professional 1.15 MailEnable MailEnable Professional 1.14 MailEnable MailEnable Professional 1.13 MailEnable MailEnable Professional 1.12 MailEnable MailEnable Professional 1.7 MailEnable MailEnable Professional 1.6 MailEnable MailEnable Professional 1.5 MailEnable MailEnable Professional 1.2 a MailEnable MailEnable Professional 1.2 a MailEnable MailEnable Professional 1.2 MailEnable MailEnable Professional 1.2 MailEnable MailEnable Professional 1.1 MailEnable MailEnable Professional 1.0 017 MailEnable MailEnable Professional 1.0 016 MailEnable MailEnable Professional 1.0 015 MailEnable MailEnable Professional 1.0 014 MailEnable MailEnable Professional 1.0 013 MailEnable MailEnable Professional 1.0 012 MailEnable MailEnable Professional 1.0 011 MailEnable MailEnable Professional 1.0 010 MailEnable MailEnable Professional 1.0 009 MailEnable MailEnable Professional 1.0 008 MailEnable MailEnable Professional 1.0 007 MailEnable MailEnable Professional 1.0 006 MailEnable MailEnable Professional 1.0 005 MailEnable MailEnable Professional 1.0 004 MailEnable MailEnable Professional 2.351 MailEnable MailEnable Professional 2.35 MailEnable MailEnable Professional 2.34 MailEnable MailEnable Professional 2.33 MailEnable MailEnable Professional 2.32 MailEnable MailEnable Professional 2.2 MailEnable MailEnable Professional 2.1 MailEnable MailEnable Professional 2.0 MailEnable MailEnable Professional 1.84 MailEnable MailEnable Professional 1.83 MailEnable MailEnable Professional 1.82 MailEnable MailEnable Professional 1.73 MailEnable MailEnable Professional 1.72 MailEnable MailEnable Enterprise Edition 1.1 MailEnable MailEnable Enterprise Edition 1.0 4 MailEnable MailEnable Enterprise Edition 1.0 3 MailEnable MailEnable Enterprise Edition 1.0 2 MailEnable MailEnable Enterprise Edition 1.0 1 MailEnable MailEnable Enterprise Edition 1.0 MailEnable MailEnable Enterprise Edition 2.35 MailEnable MailEnable Enterprise Edition 2.34 MailEnable MailEnable Enterprise Edition 2.33 MailEnable MailEnable Enterprise Edition 2.32 MailEnable MailEnable Enterprise Edition 2.2 MailEnable MailEnable Enterprise Edition 2.1 MailEnable MailEnable Enterprise Edition 2.0 MailEnable MailEnable Enterprise Edition 1.41 MailEnable MailEnable Enterprise Edition 1.40 MailEnable MailEnable Enterprise Edition 1.21 MailEnable MailEnable Enterprise Edition 1.2 MailEnable MailEnable Enterprise Edition 1.1 |
| Not Vulnerable: |
MailEnable MailEnable Professional 2.37 MailEnable MailEnable Professional 1.85 MailEnable MailEnable Enterprise Edition 2.37 MailEnable MailEnable Enterprise Edition 1.42 |
Discussion
MailEnable Web Mail Client Multiple HTML Injection and Cross-Site Scripting Vulnerabilities
MailEnable Web Mail Client is prone to multiple HTML-njection and cross-site scripting vulnerabilities because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials. The attacker could also exploit the HTML-injection issues to control how the site is rendered to the user; other attacks are also possible.
These issues affect MailEnable Professional version 2.351; other versions may also be vulnerable.
MailEnable Web Mail Client is prone to multiple HTML-njection and cross-site scripting vulnerabilities because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials. The attacker could also exploit the HTML-injection issues to control how the site is rendered to the user; other attacks are also possible.
These issues affect MailEnable Professional version 2.351; other versions may also be vulnerable.
Exploit / POC
MailEnable Web Mail Client Multiple HTML Injection and Cross-Site Scripting Vulnerabilities
An attacker can exploit this vulnerability via a web client.
An attacker can exploit this vulnerability via a web client.
Solution / Fix
MailEnable Web Mail Client Multiple HTML Injection and Cross-Site Scripting Vulnerabilities
Solution:
The vendor has released an advisory and fixes to address this issue. Please see the references for more information.
Solution:
The vendor has released an advisory and fixes to address this issue. Please see the references for more information.
References
MailEnable Web Mail Client Multiple HTML Injection and Cross-Site Scripting Vulnerabilities
References:
References:
- MailEnable Homepage (MailEnable)
- MailEnable Web Mail Client Multiple Vulnerabilities (Secunia)
- Secunia Research: MailEnable Web Mail Client Multiple Vulnerabilities (Secunia Research)