11 lines
No EOL
835 B
Text
11 lines
No EOL
835 B
Text
source: https://www.securityfocus.com/bid/10695/info
|
|
|
|
Ability Mail Server is reported prone to multiple vulnerabilities that may allow a remote attacker to carry out cross-site scripting and denial of service attacks.
|
|
|
|
The server is prone to a cross-site scripting vulnerability that may allow an attacker to execute arbitrary HTML and script code in the browser of a vulnerable user.
|
|
|
|
It is reported that the mail server is also prone to a denial of service vulnerability. This issue presents itself when an attacker establishes about 150-200 connections to various services such as SMTP, POP3, View FeaturesIMAP4, WebMail etc.
|
|
|
|
These issue are reported to affect Ability Mail Server version 1.18, however, other versions may be affected as well.
|
|
|
|
http://www.example.com/_error?id=[id]&errormsg=<script>alert(document.cookie)</script> |