KMMail E-Mail HTML Injection Vulnerability
BID:6013
Info
KMMail E-Mail HTML Injection Vulnerability
| Bugtraq ID: | 6013 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 21 2002 12:00AM |
| Updated: | Oct 21 2002 12:00AM |
| Credit: | Discovery of this issue is credited to Ulf Harnhammar <[email protected]>. |
| Vulnerable: |
kmMail kmMail 1.0 b kmMail kmMail 1.0 a kmMail kmMail 1.0 |
| Not Vulnerable: |
kmMail kmMail 1.0 b.1 |
Discussion
KMMail E-Mail HTML Injection Vulnerability
kmMail does not sufficiently sanitize HTML and script code from the body of e-mail messages. As a result, an attacker may send a malicious message to a user of kmMail that includes arbitrary HTML and script code.
This may allow an attacker to steal cookie-based authentication credentials from users of the webmail system. Other attacks are also possible.
kmMail does not sufficiently sanitize HTML and script code from the body of e-mail messages. As a result, an attacker may send a malicious message to a user of kmMail that includes arbitrary HTML and script code.
This may allow an attacker to steal cookie-based authentication credentials from users of the webmail system. Other attacks are also possible.