EmuMail Email Form Script Injection Vulnerability
BID:5824
Info
EmuMail Email Form Script Injection Vulnerability
| Bugtraq ID: | 5824 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-1526 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 29 2002 12:00AM |
| Updated: | Jul 11 2009 05:06PM |
| Credit: | Vulnerability discovery credited to FVS <[email protected]>. |
| Vulnerable: |
EMUMail EMUMail for Windows 5.0 EMUMail EMUMail for Unix 5.0 EMUMail EMUMail for Red Hat Linux 5.0 |
| Not Vulnerable: | |
Discussion
EmuMail Email Form Script Injection Vulnerability
Emumail is an open source web mail application. It is available for the Unix, Linux, and Microsoft Windows operating systems.
It has been reported that EmuMail does not properly sanitize input. Under some conditions, it is possible to pass an email containing script or html code through the EmuMail web mail interface. This would result in execution of the script code in the security context of the EmuMail site.
Emumail is an open source web mail application. It is available for the Unix, Linux, and Microsoft Windows operating systems.
It has been reported that EmuMail does not properly sanitize input. Under some conditions, it is possible to pass an email containing script or html code through the EmuMail web mail interface. This would result in execution of the script code in the security context of the EmuMail site.
Exploit / POC
EmuMail Email Form Script Injection Vulnerability
Contributed by FVS <[email protected]>:
Entering the string below into the email address field on the main form:
<script>alert(document.cookie)</script>
Contributed by FVS <[email protected]>:
Entering the string below into the email address field on the main form:
<script>alert(document.cookie)</script>
Solution / Fix
EmuMail Email Form Script Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.