Cross-site scripting (XSS) vulnerability in Open WebMail 2.x allows remote attackers to inject arbitrary HTML or web script via the domain name parameter (logindomain) in the login page.
Link | Tags |
---|---|
http://secunia.com/advisories/14253 | patch vendor advisory third party advisory |
http://www.securityfocus.com/bid/12547 | vdb entry |
http://turtle.ee.ncku.edu.tw/openwebmail/download/cert/patches/SA-05:01/2.5x.patch | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/19335 | vdb entry |
http://turtle.ee.ncku.edu.tw/openwebmail/doc/changes.txt | |
http://securitytracker.com/id?1013172 | vdb entry |