SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

MailEnable Web Mail Client MultipleVulnerabilities


Arrow  SecurityAlert : 2258
Arrow  CVE : CVE-2007-0652
Arrow  CVE : CVE-2007-0651
Arrow  SecurityRisk : Medium  Security Risk Medium  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : No
Arrow  Exploit Available : No
Arrow  Credit : Secunia Research
Arrow  Published : 19.02.2007

Arrow  Affected Software : MailEnable Professional Edition 2.351



Arrow  Advisory Content :  

======================================================================

Secunia Research 14/02/2007

- MailEnable Web Mail Client Multiple Vulnerabilities -

======================================================================
Table of Contents

Affected Software....................................................1
Severity.............................................................2
Vendor's Description of Software.....................................3
Description of Vulnerability.........................................4
Solution.............................................................5
Time Table...........................................................6
Credits..............................................................7
References...........................................................8
About Secunia........................................................9
Verification........................................................10

======================================================================
1) Affected Software

* MailEnable Professional Edition 2.351

NOTE: Other versions may also be affected.

======================================================================
2) Severity

Rating: Moderately Critical
Impact: Cross-site scripting
Where: From Remote

======================================================================
3) Vendor's Description of Software

"MailEnable's mail server software provides a powerful, scalable hosted
messaging platform for Microsoft Windows. MailEnable offers stability,
unsurpassed flexibility and an extensive feature set which allows you
to provide cost-effective mail services."

Product Link:
http://www.mailenable.com/default.asp

======================================================================
4) Description of Vulnerability

Secunia Research has discovered some vulnerabilities in MailEnable Web
Mail Client, which can be exploited by malicious people to conduct
cross-site scripting, cross-site request forgery, and script insertion
attacks.

1) Scripts in email messages are not properly sanitised before being
displayed in the email message. This can be exploited to insert
arbitrary HTML and script code, which is executed in a user's browser
session in context of an affected site when a user views a specially
crafted email message.

2) Input passed to the "ID" parameter in
mewebmail/base/default/lang/EN/right.asp,
mewebmail/base/default/lang/EN/Forms/MAI/list.asp, and
mewebmail/base/default/lang/EN/Forms/VCF/list.asp is not properly
sanitised before being returned to the user. This can be exploited to
execute arbitrary HTML and script code in a user's browser session in
context of an affected site.

Successful exploitation requires that the target user is logged in.

3) The application allows users to send messages via HTTP requests
without performing any validity checks to verify the request. This can
be exploited to change a user's settings by e.g. tricking a target user
into visiting a malicious website.

======================================================================
5) Solution

Update to the latest version.
http://www.mailenable.com/download.asp

======================================================================
6) Time Table

06/02/2007 - Vendor notified.
06/02/2007 - Vendor response.
13/02/2007 - Request for status update.
13/02/2007 - Vendor response with fix information.
14/02/2007 - Public disclosure.

======================================================================
7) Credits

Discovered by JJ Reyes, Secunia Research.

======================================================================
8) References

The Common Vulnerabilities and Exposures (CVE) project has assigned
the following CVE identifiers:
* CVE-2007-0651 (XSS)
* CVE-2007-0652 (CSRF)

======================================================================
9) About Secunia

Secunia offers vulnerability management solutions to corporate
customers with verified and reliable vulnerability intelligence
relevant to their specific system configuration:

http://corporate.secunia.com/

Secunia also provides a publicly accessible and comprehensive advisory
database as a service to the security community and private
individuals, who are interested in or concerned about IT-security.

http://secunia.com/

Secunia believes that it is important to support the community and to
do active vulnerability research in order to aid improving the
security and reliability of software in general:

http://corporate.secunia.com/secunia_research/33/

Secunia regularly hires new skilled team members. Check the URL below
to see currently vacant positions:

http://secunia.com/secunia_vacancies/

Secunia offers a FREE mailing list called Secunia Security Advisories:

http://secunia.com/secunia_security_advisories/

======================================================================
10) Verification

Please verify this advisory by visiting the Secunia website:
http://secunia.com/secunia_research/2007-38/

Complete list of vulnerability reports published by Secunia Research:
http://secunia.com/secunia_research/

======================================================================





Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc/fnmatch(3) DoS

Security Risk Medium- 2011-05-13

Allow attacker to denial of service apache 2.2.17 server

Apache RSS Apache Alert

» Apache HTTP Server Denial
   of Service Vulnerability

» Multiple Vendors
   libc/fnmatch(3) DoS (incl
   apache poc)

» Apache Continuum
   cross-site scripting
   vulnerability

» Apache Tomcat DoS
   Vulnerability

PHP RSS PHP Alert

» PHP Hashtables Denial of
   Service

» PHP 5.3.6 multiple null
   pointer dereference

» PHP 5.3.6 ZipArchive
   invalid use glob(3)

» libzip 0.9.3
   _zip_name_locate NULL
   Pointer Dereference (incl
   PHP 5.3.5)

ADT

Protect your family and valuables with Home Security Systems

Copyright © SecurityReason.com. All Rights Reserved.