NOCC Webmail View Headers HTML Injection Vulnerability
BID:6014
Info
NOCC Webmail View Headers HTML Injection Vulnerability
| Bugtraq ID: | 6014 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 14 2002 12:00AM |
| Updated: | May 14 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to Ulf Harnhammar <[email protected]>. |
| Vulnerable: |
NOCC NOCC 0.9.5 NOCC NOCC 0.9.4 NOCC NOCC 0.9.3 NOCC NOCC 0.9.2 NOCC NOCC 0.9.1 NOCC NOCC 0.9 |
| Not Vulnerable: | |
Discussion
NOCC Webmail View Headers HTML Injection Vulnerability
NOCC is a web based email client implemented in PHP4. It includes support for POP3, SMTP and IMAP servers, MIME attachments and multiple languages.
A script injection issue has been reported with the way email message headers are displayed to users of NOCC webmail. A malicious attacker can include script code in an email and potentially get full access to a victim's mailbox.
NOCC is a web based email client implemented in PHP4. It includes support for POP3, SMTP and IMAP servers, MIME attachments and multiple languages.
A script injection issue has been reported with the way email message headers are displayed to users of NOCC webmail. A malicious attacker can include script code in an email and potentially get full access to a victim's mailbox.
Solution / Fix
NOCC Webmail View Headers HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.