|
|
| |
| VPOP3 is "an Internet email server and gateway for small and medium sized businesses". A security vulnerability in the product allows remote attackers to steal the authentication cookie stored by the server, by inserting malicious HTML and/or JavaScript into the login page. |
| |
Credit:
The information has been provided by SecurITeam Experts.
|
| |
Vulnerable systems:
* VPOP3 version 2.0.0e
* VPOP3 version 2.0.0f
Immune systems:
* VPOP3 version 2.0.0g
By requesting a specially crafted URL, it is possible to cause the VPOP3's Web Mail server to return arbitrary HTML and/or JavaScript, by using a URL such as: http://192.168.1.212:5108/index.html?redirect=admin/index.html";%0Dalert(document.cookie);%0D//
It is possible to steal the cookie (used for authentication) from a user (preferably the administrator) and to impersonate him.
|
|
|
|
|