Exploit Outblaze Webmail - HTML Injection

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
24291
Проверка EDB
  1. Пройдено
Автор
DARKBICHO
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2004-2625
Дата публикации
2004-07-19
Outblaze Webmail - HTML Injection
Код:
source: https://www.securityfocus.com/bid/10756/info

Outblaze Webmail is reported prone to an-HTML injection vulnerability because the application fails to properly sanitize user-supplied HTML email content.

An attacker may be able to inject HTML and script code into the application through HTML email because it isn't properly sanitized.

An attacker can exploit this issue to access an unsuspecting user's cookie-based authentication credentials and to retrieve personal email. Other attacks are also possible.

<IMG SRC="javasc&#X0A;ript:alert (document.cookie)";" border="0" height="1" width="1">
 
Источник
www.exploit-db.com

Похожие темы