Jump to content
Praetorian503

Alt-N MDaemon Email Body Cross Site Scripting

Recommended Posts

Alt-N MDaemon version 13.0.3 suffers from a cross site scripting vulnerability in the email body due to a lack of sanitization.

==============================================================
Alt-N MDaemon Email Body HTML/JS Injection Vulnerability
==============================================================

Software: Alt-N MDaemon v13.0.3 and prior versions
Vendor: http://www.altn.com/
Vuln Type: HTML/JS Injection
Remote: Yes
Local: No
Discovered by: QSecure and Demetris Papapetrou
References: http://www.qsecure.com.cy/advisories/Alt-N_MDaemon_Email_Body_HTML_JS_Injection.html
Discovered: 14/09/2012
Reported: 19/12/2012
Fixed: 15/01/2013 (http://files.altn.com/MDaemon/Release/RelNotes_en.html)
Disclosed: 18/02/2013

VULNERABILITY DESCRIPTION:
==========================
Alt-N MDaemon is prone to an HTML/Javascript injection vulnerability
because it fails to sanitize user-supplied input.

Attacker-supplied HTML and/or JavaScript code could run in the context
of the affected site, potentially allowing the attacker to steal
cookie-based authentication credentials and control how the site is
rendered to the user; other attacks are also possible.

Alt-N MDaemon v13.0.3 & v12.5.6 were tested and found vulnerable;
other versions may also be affected.

PoC Exploit:
============
<<!-------->script>alert('XSS');<<!-------->/script>

Source: PacketStorm

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...