Merak Mail Server and Webmail Email Message HTML Injection Vulnerability
BID:32969
Info
Merak Mail Server and Webmail Email Message HTML Injection Vulnerability
| Bugtraq ID: | 32969 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-5734 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 22 2008 12:00AM |
| Updated: | Dec 31 2008 09:02PM |
| Credit: | Nenad Vijatov |
| Vulnerable: |
IceWarp Web Mail 5.6.1 IceWarp Web Mail 5.6.1 IceWarp Web Mail 5.6 IceWarp Web Mail 5.6 IceWarp Web Mail 5.5.1 IceWarp Web Mail 5.4 IceWarp Web Mail 5.3.2 IceWarp Web Mail 5.3.1 IceWarp Web Mail 5.3 IceWarp Web Mail 5.2.8 IceWarp Web Mail 5.2.7 IceWarp Merak Mail Server 9.3.2 IceWarp Merak Mail Server 9.0 IceWarp Merak Mail Server 8.9.2 IceWarp Merak Mail Server 8.9.1 |
| Not Vulnerable: |
IceWarp Merak Mail Server 9.4 |
Discussion
Merak Mail Server and Webmail Email Message HTML Injection Vulnerability
Merak Mail Server and Webmail are prone to an HTML-injection vulnerability because the applications fail to sufficiently sanitize user-supplied input before using it in dynamically generated content.
Exploiting this issue may allow an attacker to execute HTML and script code in the context of the affected site, to steal cookie-based authentication credentials, or to control how the site is rendered to the user; other attacks are also possible.
Merak Mail Server and Webmail are prone to an HTML-injection vulnerability because the applications fail to sufficiently sanitize user-supplied input before using it in dynamically generated content.
Exploiting this issue may allow an attacker to execute HTML and script code in the context of the affected site, to steal cookie-based authentication credentials, or to control how the site is rendered to the user; other attacks are also possible.
Exploit / POC
Merak Mail Server and Webmail Email Message HTML Injection Vulnerability
Attackers can exploit this issue by sending malicious emails to unsuspecting victims and enticing them to open the mail.
Attackers can exploit this issue by sending malicious emails to unsuspecting victims and enticing them to open the mail.
Solution / Fix
Merak Mail Server and Webmail Email Message HTML Injection Vulnerability
Solution:
The vendor released an update to address this issue. Please contact the vendor for details.
Solution:
The vendor released an update to address this issue. Please contact the vendor for details.
References
Merak Mail Server and Webmail Email Message HTML Injection Vulnerability
References:
References:
- Merak Mail Server Homepage (IceWarp)