Message Foundry Multiple Vulnerabilities
BID:8229
Info
Message Foundry Multiple Vulnerabilities
| Bugtraq ID: | 8229 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jul 17 2003 12:00AM |
| Updated: | Jul 17 2003 12:00AM |
| Credit: | Discovery is credited to Ziv Kamir. |
| Vulnerable: |
Application Foundry Message Foundry 2.75 .0003 |
| Not Vulnerable: | |
Discussion
Message Foundry Multiple Vulnerabilities
Message Foundry is reportedly prone to multiple vulnerabilities.
An HTML injection vulnerability was reported that can be exploited by submitting a value for the "NAME" input field that contains HTML and script code. This could permit execution of hostile HTML and script code in the security context of the site hosting the software.
The software is also reported to store the administrative password in plaintext in the MF.ini file.
An additional issue is reported that may permit an attacker to change another user's password if they are in the say public or private area of an affected site.
Message Foundry is reportedly prone to multiple vulnerabilities.
An HTML injection vulnerability was reported that can be exploited by submitting a value for the "NAME" input field that contains HTML and script code. This could permit execution of hostile HTML and script code in the security context of the site hosting the software.
The software is also reported to store the administrative password in plaintext in the MF.ini file.
An additional issue is reported that may permit an attacker to change another user's password if they are in the say public or private area of an affected site.