Roundcube Webmail CSS Expression Input Validation Vulnerability
BID:26800
Info
Roundcube Webmail CSS Expression Input Validation Vulnerability
| Bugtraq ID: | 26800 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6321 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 10 2007 12:00AM |
| Updated: | Apr 13 2015 09:38PM |
| Credit: | Tomas Kuliavas is credited with the discovery of this issue. |
| Vulnerable: |
Roundcube Round Cube Webmail 0.1Rc2 Redhat Fedora 7 |
| Not Vulnerable: | |
Discussion
Roundcube Webmail CSS Expression Input Validation Vulnerability
Roundcube Webmail is prone to an input-validation vulnerability because it fails to sanitize HTML email messages.
Attackers can exploit this issue to execute arbitrary script code in the browser of an unsuspecting user. Successful attacks can allow attackers to steal cookie-based authentication credentials from legitimate users of the site; other attacks are also possible.
Roundcube Webmail 0.1rc2 is vulnerable; other versions may also be affected.
Roundcube Webmail is prone to an input-validation vulnerability because it fails to sanitize HTML email messages.
Attackers can exploit this issue to execute arbitrary script code in the browser of an unsuspecting user. Successful attacks can allow attackers to steal cookie-based authentication credentials from legitimate users of the site; other attacks are also possible.
Roundcube Webmail 0.1rc2 is vulnerable; other versions may also be affected.
Exploit / POC
Roundcube Webmail CSS Expression Input Validation Vulnerability
Attackers can exploit this issue via a browser.
The following proof-of-concept code is available:
Attackers can exploit this issue via a browser.
The following proof-of-concept code is available:
Solution / Fix
Roundcube Webmail CSS Expression Input Validation Vulnerability
Solution:
Vendor advisories are available. Please see the references for more information.
Solution:
Vendor advisories are available. Please see the references for more information.
References
Roundcube Webmail CSS Expression Input Validation Vulnerability
References:
References:
- Vendor Homepage (RoundCube Project)
- Unsanitized scripting in RoundCube webmail (Tomas Kuliavas
)