PSCS VPOP3 Email Message HTML Injection Vulnerability
BID:33558
Info
PSCS VPOP3 Email Message HTML Injection Vulnerability
| Bugtraq ID: | 33558 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 02 2009 12:00AM |
| Updated: | Feb 03 2009 05:59PM |
| Credit: | Nenad Vijatov |
| Vulnerable: |
PSCS VPOP3 2.6.0i PSCS VPOP3 2.6.0h |
| Not Vulnerable: | |
Discussion
PSCS VPOP3 Email Message HTML Injection Vulnerability
PSCS VPOP3 is prone to an HTML-injection vulnerability because the application fails to sufficiently sanitize user-supplied input before using it in dynamically generated content.
Exploiting this issue may allow an attacker to execute HTML and script code in the context of the affected site, to steal cookie-based authentication credentials, or to control how the site is rendered to the user; other attacks are also possible.
PSCS VPOP3 is prone to an HTML-injection vulnerability because the application fails to sufficiently sanitize user-supplied input before using it in dynamically generated content.
Exploiting this issue may allow an attacker to execute HTML and script code in the context of the affected site, to steal cookie-based authentication credentials, or to control how the site is rendered to the user; other attacks are also possible.
Exploit / POC
PSCS VPOP3 Email Message HTML Injection Vulnerability
Attackers can exploit this issue by sending malicious email to unsuspecting victims and enticing them to open it.
Attackers can exploit this issue by sending malicious email to unsuspecting victims and enticing them to open it.
Solution / Fix
PSCS VPOP3 Email Message HTML Injection Vulnerability
Solution:
The vendor indicates that this issue has been fixed in VPOP3 2.6.0i, but third-party reports indicate that this issue has not been completely fixed. Please see the references for more information.
Solution:
The vendor indicates that this issue has been fixed in VPOP3 2.6.0i, but third-party reports indicate that this issue has not been completely fixed. Please see the references for more information.
References
PSCS VPOP3 Email Message HTML Injection Vulnerability
References:
References: