[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Alt-N MDaemon 13.0.3 and 12.5.6 Email Body HTML/JS Injection Vulnerability

Author
QSecure
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-20418
Category
web applications
Date add
21-02-2013
Platform
windows
VULNERABILITY DESCRIPTION:
==========================
Alt-N MDaemon is prone to an HTML/Javascript injection vulnerability
because it fails to sanitize user-supplied input.
 
Attacker-supplied HTML and/or JavaScript code could run in the context
of the affected site, potentially allowing the attacker to steal
cookie-based authentication credentials and control how the site is
rendered to the user; other attacks are also possible.
 
Alt-N MDaemon v13.0.3 & v12.5.6 were tested and found vulnerable;
other versions may also be affected.
 
PoC Exploit:
============
<<!-------->script>alert('XSS');<<!-------->/script>?iref=allsearch

#  0day.today [2024-09-28]  #