Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

OpenWebmail openwebmail.pl logindomain Parameter XSS

Medium

Synopsis

The remote host is running OpenWebmail, an open-source perl script that gives remote users a web-based interface to email.

Description

The remote host is running OpenWebmail, an open-source perl script that gives remote users a web-based interface to email. This version of OpenWebmail is vulnerable to a cross-site scripting (XSS) attack. An attacker exploiting this flaw would be need to be able to convince a user to click on a malicious URL. Upon successful exploitation, the attacker would be able to steal credentials or execute code within the browser.

Solution

Upgrade or patch according to vendor recommendations.