Software602 602Pro LAN Suite Web Mail Cross-Site Scripting Vulnerability
BID:9777
Info
Software602 602Pro LAN Suite Web Mail Cross-Site Scripting Vulnerability
| Bugtraq ID: | 9777 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-0337 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 01 2004 12:00AM |
| Updated: | Jul 12 2009 03:06AM |
| Credit: | Disclosure of this issue is credited to Rafel Ivgi, The-Insider <[email protected]>. |
| Vulnerable: |
Software602 602Pro LAN SUITE 2003 Software602 602Pro LAN SUITE 2002 |
| Not Vulnerable: | |
Discussion
Software602 602Pro LAN Suite Web Mail Cross-Site Scripting Vulnerability
It has been reported that 602Pro LAN Suite Web Mail is prone to a cross-site scripting vulnerability. This issue is due to a failure of the application to properly sanitize user input supplied via the URI.
Attackers may exploit this vulnerability to steal authentication credentials. Other attacks may also be possible.
**The vendor has stated that they were unable to reproduce this issue, therefore, this BID has been changed to conflicting reports. This issue will be updated as more information becomes available.
It has been reported that 602Pro LAN Suite Web Mail is prone to a cross-site scripting vulnerability. This issue is due to a failure of the application to properly sanitize user input supplied via the URI.
Attackers may exploit this vulnerability to steal authentication credentials. Other attacks may also be possible.
**The vendor has stated that they were unable to reproduce this issue, therefore, this BID has been changed to conflicting reports. This issue will be updated as more information becomes available.
Exploit / POC
Software602 602Pro LAN Suite Web Mail Cross-Site Scripting Vulnerability
No exploit is required to leverage this issue. The following proof of concept has been provided.
http://www.example.com/index.html/<script>alert('XSS')</script>
No exploit is required to leverage this issue. The following proof of concept has been provided.
http://www.example.com/index.html/<script>alert('XSS')</script>
Solution / Fix
Software602 602Pro LAN Suite Web Mail Cross-Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Software602 602Pro LAN Suite Web Mail Cross-Site Scripting Vulnerability
References:
References:
- 602Pro Lan Suite Product Information Page (Software602)
- LAN SUITE Web Mail (Rafel Ivgi, The-Insider
) - Re: LAN SUITE Web Mail 602Pro Multiple Vulnerabilities (Brandon Sturgeon
)