Release date:
Updated on:
Affected Systems:
@ Mail Atmail Webmail Client 6.3.4
@ Mail AtMail Webmail 6.3.4
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51303
Atmail is a provider of commercial Linux message transmission platform.
Atmail Webmail does not properly filter user input before using it as dynamic content. Multiple HTML injection vulnerabilities exist in implementation, successful exploitation allows attackers to execute arbitrary HTML and script code in the user's browser of the affected site to steal Cookie authentication creden。 or control the site appearance.
<* Source: Benjamin Kunz Mejri
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
@ Mail
-----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.securityfocus.com/bid/51313/www.atmail.com