Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Open WebMail Logindomain Parameter Cross-Site Scripting Vulnerability

Open WebMail is prone to a cross-site scripting vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied URI input.

The problem presents itself when malicious HTML and script code is sent to the application through the 'logindomain' parameter.

This vulnerability has been reported to exist in Open WebMail versions 2.50 20050212 and prior.







 

Privacy Statement
Copyright 2009, SecurityFocus