AfterLogic WebMail Pro Multiple Cross Site Scripting Vulnerabilities
BID:36605
Info
AfterLogic WebMail Pro Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 36605 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 06 2009 12:00AM |
| Updated: | Oct 07 2009 03:29PM |
| Credit: | Sebastien Duquette |
| Vulnerable: |
AfterLogic WebMail Pro 4.7.10 |
| Not Vulnerable: | |
Discussion
AfterLogic WebMail Pro Multiple Cross Site Scripting Vulnerabilities
AfterLogic WebMail Pro is prone to multiple cross-site scripting vulnerabilities because the application fails to sufficiently sanitize user-supplied data.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials; other attacks are also possible.
AfterLogic WebMail Pro 4.7.10 and prior versions are affected.
AfterLogic WebMail Pro is prone to multiple cross-site scripting vulnerabilities because the application fails to sufficiently sanitize user-supplied data.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials; other attacks are also possible.
AfterLogic WebMail Pro 4.7.10 and prior versions are affected.
Exploit / POC
AfterLogic WebMail Pro Multiple Cross Site Scripting Vulnerabilities
An attacker can exploit these issues by enticing an unsuspecting victim to visit a malicious website.
The following exploit is available:
An attacker can exploit these issues by enticing an unsuspecting victim to visit a malicious website.
The following exploit is available:
Solution / Fix
AfterLogic WebMail Pro Multiple Cross Site Scripting Vulnerabilities
Solution:
Reports indicate that the vendor addressed these issues in WebMail Pro 4.7.11, but Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reports indicate that the vendor addressed these issues in WebMail Pro 4.7.11, but Symantec has not confirmed this. Please contact the vendor for more information.
References
AfterLogic WebMail Pro Multiple Cross Site Scripting Vulnerabilities
References:
References:
- Vendor Homepage (Afterlogic)