Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  Cireos Portal Cross Site Scripting

  [SA19870] Trac Wiki Macro Script Insertion Vulnerability

  [SA19849] Network Administration Visualized SQL Injection Vulnerability

  [SA19824] Phex Chat Request Handling Weakness

From:r0t <krustevs_(at)_googlemail.com>
Date:28.04.2006
Subject:Open WebMail <=2.51 XSS vuln.

Open WebMail <=2.51 XSS vuln.


###############################################
Vulnerability discovered by : r0t
Date: 27 april 2006
vendorlink:http://openwebmail.org/
affected versions:2.51 and prior
orginal advisory:
http://pridels.blogspot.com/2006/04/open-webmail-251-xss-vuln.html
###############################################


Vuln. Description:


Open WebMail contains a flaw that allows a remote cross site scripting
attack. This flaw exists because input passed to "sessionid" paremeter in "
openwebmail-send.pl",
"openwebmail-advsearch.pl","openwebmail-folder.pl",
"openwebmail-prefs.pl",
"openwebmail-abook.pl","openwebmail-main.pl",
"openwebmail-read.pl","
openwebmail-cal.pl","openwebmail-webdisk.pl"  isn't properly sanitised
before being returned to the user.
This could allow a user to create a specially crafted URL that would execute
arbitrary code in a user's browser within the trust relationship between the
browser and the server, leading to a loss of integrity.

examples:

/openwebmail-send.pl?sessionid=[XSS]
/openwebmail-advsearch.pl?sessionid=[XSS]
/openwebmail-folder.pl?action=editfolders&sessionid=[XSS]
/openwebmail-prefs.pl?action=editprefs&sessionid=[XSS]
/openwebmail-abook.pl?sessionid=[XSS]
/openwebmail-main.pl?sessionid=[XSS]
/openwebmail-read.pl?sessionid=[XSS]
/openwebmail-cal.pl?sessionid=[XSS]
/openwebmail-webdisk.pl?action=showdir&sessionid=[XSS]


###############################################
Solution:
Edit the source code to ensure that input is properly sanitised.
###############################################
More information @ unsecured-systems.com/forum/

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server