PT-2012-4119 · Mailtraq · Mailtraq
Loneferret
·
Publicado
2012-09-19
·
Atualizado
2012-10-26
·
CVE-2012-2586
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Mailtraq version 2.17.3.3150
Description
The issue allows remote attackers to inject arbitrary web script or HTML via various components of an e-mail message, including the subject, body, and Date header. This can be achieved through different methods, such as using a JavaScript alert function with the fromCharCode method, incorporating a SCRIPT element, or utilizing a crafted SRC attribute of an IFRAME element. Additionally, attackers can exploit this by using a data: URL in the CONTENT attribute of an HTTP-EQUIV="refresh" META element or by leveraging a Cascading Style Sheets (CSS) expression property in the STYLE attribute of an element, such as an IMG element.
Recommendations
For Mailtraq version 2.17.3.3150, consider disabling the rendering of JavaScript and HTML elements within e-mail messages to minimize the risk of exploitation. Restrict access to potentially vulnerable components, such as the IFRAME element and META elements with HTTP-EQUIV="refresh", until a patch is available. Avoid using CSS expression properties in the STYLE attribute of elements within e-mail messages until the issue is resolved.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Mailtraq