Vulnerability Scanning Solutions, LLC.
Our Process
What We Scan For
Sample Report
Client List
Contact Us
What We Scan For
Family: Gentoo Local Security Checks --> Category: infos

[GLSA-200408-02] Courier: Cross-site scripting vulnerability in SqWebMail Vulnerability Scan

Vulnerability Scan Summary
Courier: Cross-site scripting vulnerability in SqWebMail

Detailed Explanation for this Vulnerability Test
The remote host is affected by the vulnerability described in GLSA-200408-02
(Courier: Cross-site scripting vulnerability in SqWebMail)

Luca Legato found that SqWebMail is vulnerable to a cross-site scripting
(XSS) attack. An XSS attack allows a possible hacker to insert malicious code
into a web-based application. SqWebMail doesn't filter appropriately data
coming from message headers before displaying them.


By sending a carefully crafted message, a possible hacker can inject and execute
script code in the victim's browser window. This allows to modify the
behaviour of the SqWebMail application, and/or leak session information
such as cookies to the attacker.


There is no known workaround at this time. All users are encouraged to
upgrade to the latest available version of Courier.


All Courier users should upgrade to the latest version:
# emerge sync
# emerge -pv ">=mail-mta/courier-"
# emerge ">=mail-mta/courier-"

Threat Level: Medium

Click HERE for more information and discussions on this network vulnerability scan.


P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.