Bug#327181: SqWebMail Conditional Comments Script Insertion Vulnerability

2005-09-12 Thread Stefan Hornburg
On Thu, 8 Sep 2005 10:06:53 +0200 Stefan Hornburg <[EMAIL PROTECTED]> wrote: > package: sqwebmail > severity: important > tags: security > > Secunia Research has discovered a vulnerability in SqWebMail, which > can be exploited by malicious people to conduct script insertion > attacks. > > The v

Bug#327181: SqWebMail Conditional Comments Script Insertion Vulnerability

2005-09-08 Thread Stefan Hornburg
package: sqwebmail severity: important tags: security Secunia Research has discovered a vulnerability in SqWebMail, which can be exploited by malicious people to conduct script insertion attacks. The vulnerability is caused due to SqWebMail allowing usage of e.g. the "" tag within an HTML comment