|
Family: CGI abuses --> Category: infos
HastyMail HTML Attachement Script Execution Vulnerability Scan
Vulnerability Scan Summary Checks for version of HastyMail
Detailed Explanation for this Vulnerability Test
The remote host is running HastyMail, a PHP-based mail client application.
There is a flaw in the remote version of this software which may allow
a possible hacker to execute arbitrary javascript code on the hosts of users
of this software.
To exploit this flaw, a possible hacker would need to send an email to a victim
using HastyMail containing a malicious HTML attachment. When the victim attempts
to read the attachment, his browser may attempt to render the HTML file.
A possible hacker may use this flaw to steal the cookies of the victim and
therefore get access to his mailbox, or may perform other attacks.
Solution : Upgrade to HastyMail 1.0.2 or 1.2.0
Risk factor: Medium
Click HERE for more information and discussions on this network vulnerability scan.
|