A reflected XSS vulnerability was detected in the login process of the Atmail WebMail, that allows the execution of arbitrary HTML/script code to be executed in the context of the victim user's browser. The code injection is done through the "MailType" parameter, and can be exploited without a user account in the WebMail. Moreover, the login request may be made by the HTTP GET method (by default, HTTP POST method is used), so this facilitates the exploitation of the vulnerability.
Disclosure Timeline:
August 30, 2010: Initial release
September 21, 2010: Last revision