|
Brought to you by:
Suppliers of:
|
|
|
| |
| Mail.com offers free webmail services, which are used by tens of thousands of people around the world. The site suffers from a CSS vulnerability, giving a malicious user the ability to view the site cookies of any user currently logged in. |
| |
Credit:
The information has been provided by Ministry-of-Peace.
|
| |
Impact:
If a malicious user can get the mail.com user to follow a simple link, then they can grab that users mail.com cookies and possibly use them to authenticate as that user.
Example:
Log into your mail.com account, and then go to:
http://mymail.mail.com/scripts/common/forgotpasswd.cgi?login=<p><scripts>document.writeln(document.cookie)</scripts --></p>
Vendor response:
The issue was fixed as of 4th of January 2002.
|
|
|
|
|