Search:     Advanced search
server monitoring

IMP Content-Type XSS Vulnerability

Article ID: 12263
Last updated: 27 Jan, 2009
Views: 438
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

IMP Content-Type XSS Vulnerability

This script is Copyright (C) 2004-2008 George A. Theall

FamilyCGI abuses : XSS
Plugin ID12263
Bugtraq ID10501
CVE IDCVE-2004-0584

Description:

The remote server is running at least one instance of IMP whose version
number is between 2.0 and 3.2.3 inclusive. Such versions are vulnerable
to a cross-scripting attack whereby an attacker may be able to cause a
victim to unknowingly run arbitrary JavaScript code simply by reading a
MIME message with a specially crafted Content-Type header.

For information about the vulnerability, including exploits, see :

- http://www.rs-labs.com/adv/RS-Labs-Advisory-2004-2.txt
- http://www.rs-labs.com/adv/RS-Labs-Advisory-2004-1.txt

Note : has determined the vulnerability exists on the target
simply by looking at the version number of IMP installed there
it has
not attempted to actually exploit the vulnerability.

Solution : Upgrade to IMP version 3.2.4 or later.
Risk factor : High
This article was:   Helpful | Not Helpful
Prev   Next
Adobe Flex History Management Cross-Site Scripting     CommuniGate Pro WebMail w/ MSIE STYLE Tag XSS