Release date:
Updated on:
Affected Systems:
@ Mail Atmail Email Server 6.30.4
Unaffected system:
@ Mail Atmail Email Server 6.30.5
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51413
Atmail is a provider of commercial Linux message transmission platform.
The Atmail Email Server has multiple HTML Injection Vulnerabilities. After successful exploitation, attackers can run HTML and script code in the affected browsers to steal Cookie authentication creden。 or control the appearance of the site.
<* Source: vendor
Link: http://secunia.com/advisories/47440/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
@ Mail
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.securityfocus.com/bid/51313/www.atmail.com