Atmail Email Server HTML Injection Vulnerability
BID:54667
Info
Atmail Email Server HTML Injection Vulnerability
| Bugtraq ID: | 54667 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 25 2012 12:00AM |
| Updated: | Mar 19 2015 09:10AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Atmail Email Server HTML Injection Vulnerability
Atmail Email Server is prone to an HTML-injection vulnerability.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
Versions prior to Atmail Email Server 6.5.0 are vulnerable.
Atmail Email Server is prone to an HTML-injection vulnerability.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
Versions prior to Atmail Email Server 6.5.0 are vulnerable.
Exploit / POC
Atmail Email Server HTML Injection Vulnerability
Attackers can exploit this issue through a browser.
Attackers can exploit this issue through a browser.
Solution / Fix
Atmail Email Server HTML Injection Vulnerability
Solution:
Vendor updates are available. Please see the references for details.
Solution:
Vendor updates are available. Please see the references for details.
References
Atmail Email Server HTML Injection Vulnerability
References:
References:
- Atmail Email Server Homepage (Atmail)
- Atmail Server Changelog (Atmail)