Search:     Advanced search
server monitoring

CommuniGate Pro WebMail w/ MSIE STYLE Tag XSS

Article ID: 25215
Last updated: 27 Jan, 2009
Views: 448
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

CommuniGate Pro WebMail w/ MSIE STYLE Tag XSS

This script is Copyright (C) 2007-2008 Tenable Network Security, Inc.

FamilyCGI abuses : XSS
Plugin ID25215
Bugtraq ID23950
CVE IDCVE-2007-2718

Description:

Synopsis :

The remote web server is affected by a cross-site scripting issue.

Description :

According to its banner, the version of CommuniGate Pro running on the
remote host fails to completely sanitize email messages. A remote
attacker may be able to leverage this issue to inject arbitrary HTML
and script code into a users browser to be evaluated within the
security context of the affected web site.

See also :

http://archives.neohapsis.com/archives/fulldisclosure/2007-05/0186.html
http://www.communigate.com/CommuniGatePro/History51.html

Solution :

Upgrade to CommuniGate Pro version 5.1.9 or later.

Risk factor :

Medium / CVSS Base Score : 4.3
(CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)
This article was:   Helpful | Not Helpful
Prev   Next
IMP Content-Type XSS Vulnerability     SqWebMail HTTP Response Splitting Vulnerability