OSVDB ID: 15506

Title: IlohaMail read_message.php Attachment Multiple Field Script Insertion

Info

Disclosure

Apr 14, 2005

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

IlohaMail contains a flaw which can be exploited by malicious people to conduct script insertion attacks. This flaw exists due to an input validation error in the read_message.php script when processing mails where the body, filename and MIME media type of attachments isn't properly sanitized before being displayed. This could allow a user to create a specially crafted mail that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Confidentiality, Loss of Integrity
Solution: Upgrade
Exploit: Exploit Unknown
Disclosure: OSVDB Verified, Vendor Verified
OSVDB: Web Related

Solution

Upgrade to version 0.8.14-RC3 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

IlohaMail

IlohaMail

0.7 .0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.6
0.8.7
0.8.8
0.8.9
0.8.10
0.8.11
0.8.12
0.8.13
0.8.14 RC1
0.8.14 RC2
0.7 .0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.6
0.8.7
0.8.8
0.8.9
0.8.10
0.8.11
0.8.12
0.8.13
0.8.14 RC1
0.8.14 RC2

References

Credit

  • Ulf Harnhammar - metaurprontomail.com -
  • Ulf Harnhammar - metaurprontomail.com -


Direct URL: http://osvdb.org/15506