Active! Mail Cross Site Scripting and Information Disclosure Vulnerabilities
BID:37252
Info
Active! Mail Cross Site Scripting and Information Disclosure Vulnerabilities
| Bugtraq ID: | 37252 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 08 2009 12:00AM |
| Updated: | Dec 10 2009 10:24PM |
| Credit: | Maebashi Keniti, Ministry of Information Sciences Hosei University |
| Vulnerable: |
Transware Active! Mail 2003.139.871 Transware Active! Mail 2003 |
| Not Vulnerable: |
Transware Active! Mail 6 |
Discussion
Active! Mail Cross Site Scripting and Information Disclosure Vulnerabilities
Active! Mail is prone to cross-site scripting vulnerabilities and an information-disclosure vulnerability because it fails to properly validate user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks. The attacker may also obtain sensitive session information.
Active! Mail 2003.0139.0871 is vulnerable; other versions may also be affected.
Active! Mail is prone to cross-site scripting vulnerabilities and an information-disclosure vulnerability because it fails to properly validate user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks. The attacker may also obtain sensitive session information.
Active! Mail 2003.0139.0871 is vulnerable; other versions may also be affected.
Exploit / POC
Active! Mail Cross Site Scripting and Information Disclosure Vulnerabilities
An attacker may exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim into following a malicious URI.
An attacker may exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
Active! Mail Cross Site Scripting and Information Disclosure Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Active! Mail Cross Site Scripting and Information Disclosure Vulnerabilities
References:
References:
- Active! Mail Homepage (TransWARE)
- JVN#49083120 Active! mail 2003 (JVN)
- JVN#85821104 Active! mail 2003 (JVN)