|
SqWebMail Conditional Comments Script Insertion |
|
|
|
|
Wednesday, 07 September 2005 |
Summary
Secunia Research has discovered a vulnerability in SqWebMail, which can be exploited by malicious people to conduct script insertion attacks.
Credit:
The information has been provided by Secunia Research.
The original article can be found at: http://secunia.com/secunia_research/2005-44/advisory/
Details
Vulnerable Systems:
* SqWebMail version 5.0.4
The vulnerability is caused due to SqWebMail allowing usage of e.g. the "
Solution:
The vendor has issued an updated version of SqWebMail, which fixes this vulnerability: http://www.courier-mta.org/?download.php.
Disclosure Timeline:
05/09/2005 - Initial vendor notification
05/09/2005 - Vendor confirms vulnerability and releases a fix
06/09/2005 - Public disclosure |