BasiliX Webmail Message Content Script Injection Vulnerability
BID:5060
Info
BasiliX Webmail Message Content Script Injection Vulnerability
| Bugtraq ID: | 5060 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2002 12:00AM |
| Updated: | Jun 19 2002 12:00AM |
| Credit: | Discovered by Ulf Harnhammar <[email protected]>. |
| Vulnerable: |
Basilix Webmail 1.1 .0 |
| Not Vulnerable: | |
Discussion
BasiliX Webmail Message Content Script Injection Vulnerability
BasiliX is a web-based mail application. It offers features such as mail attachments, address book, multiple language and theme support.
A script injection issue has been reported in BasiliX Webmail. Script commands are not filtered from the Subject or message body, and may execute in the context of the BasiliX site when the content is viewed.
This has been reported in BasiliX Webmail 1.1.0, earlier versions may also be affected.
BasiliX is a web-based mail application. It offers features such as mail attachments, address book, multiple language and theme support.
A script injection issue has been reported in BasiliX Webmail. Script commands are not filtered from the Subject or message body, and may execute in the context of the BasiliX site when the content is viewed.
This has been reported in BasiliX Webmail 1.1.0, earlier versions may also be affected.
Solution / Fix
BasiliX Webmail Message Content Script Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.