Search:     Advanced search
server monitoring

SqWebMail HTTP Response Splitting Vulnerability

Article ID: 18372
Last updated: 27 Jan, 2009
Views: 427
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

SqWebMail HTTP Response Splitting Vulnerability

This script is Copyright (C) 2005-2008 Tenable Network Security

FamilyCGI abuses : XSS
Plugin ID18372
Bugtraq ID13374
CVE IDCVE-2005-1308

Description:
Synopsis :

The remote web server contains a CGI script that is affected by a
cross-site scripting flaw.

Description :

The remote host is running a version of SqWebMail that does not
properly sanitize user-supplied input through the redirect
parameter. An attacker can exploit this flaw to inject arbitrary HTML
and script code into a users browser to be executed within the
context of the affected web site. Such attacks could lead to session
cookie and password theft for users who read mail with SqWebMail.

See also :

http://archives.neohapsis.com/archives/bugtraq/2005-04/0440.html

Solution :

Unknown at this time.

Risk factor:

Medium / CVSS Base Score : 4.3
(CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)
This article was:   Helpful | Not Helpful
Prev   Next
CommuniGate Pro WebMail w/ MSIE STYLE Tag XSS     CoolPHP Multiple Vulnerabilities