EmailArchitect Email Server Multiple HTML Injection Vulnerabilities
13 Aug. 2012
Summary
EmailArchitect Email Server is prone to multiple HTML-injection vulnerabilities because it fails to properly validate user-supplied input.
Credit:
The original article can be found at: http://www.securityfocus.com/bid/54896
The information has been provided by Mateusz Jurczyk and Gynvael Coldwind .
Vulnerable Systems:
*EmailArchitect Email Server Multiple HTML Injection Vulnerabilities
An attacker may leverage these issues to inject hostile HTML and script code that would run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user.EmailArchitect Email Server 10.0 is vulnerable; other versions may also be affected.
Vendor Status:
Vendor as issued an updated vulnerability.