KMMail 1.0 - E-Mail HTML Injection



EKU-ID: 27450 CVE: CVE-2002-1958;OSVDB-59315 OSVDB-ID:
Author: Ulf Harnhammar Published: 2002-10-21 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/6013/info

kmMail does not sufficiently sanitize HTML and script code from the body of e-mail messages. As a result, an attacker may send a malicious message to a user of kmMail that includes arbitrary HTML and script code.

This may allow an attacker to steal cookie-based authentication credentials from users of the webmail system. Other attacks are also possible.

<b onMouseOver="alert(document.location)">bolder</b>