Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

NOCC Webmail Script Injection Vulnerability

NOCC is a web based email client implemented in PHP4. It includes support for POP3, SMTP and IMAP servers, MIME attachments and multiple languages.

A script injection issue has been reported with the way emails are displayed to users of NOCC webmail. A malicious attacker can include script code in an email and potentially get full access to a victim's mailbox.







 

Privacy Statement
Copyright 2009, SecurityFocus