UebiMiau 2.7.9 (latest release) and probably previous versions.
Advisory Text :
I.Vulnerability
UebiMiau Webmail System Cross Site Scripting Vulnerability
II.Vendor
Aldoir Ventura
III.Affected Systems
* UebiMiau 2.7.9 (latest release) and probably previous versions.
IV.About
UebiMiau is a simple, yet efficient mail reader (webmail) supporting both
IMAP and POP3 without dependence of any PHP's extra modules or database
(http://www.uebimiau.org).
V.Description
UebiMiau does not filter HTML e-mail messages correctly, it's possible to
inject mailicious scripting codes to an e-mail. An attacker is able to
hijack a user's session and access victim's mailbox just by sending a
specially crafted e-mail message.
This is a dangerous situation because there is no need to click a link in
some cases, client-side code executing when the user opens crafted e-mail.
link 1</a>
<a href='http://ATTACKER/StealData/'>test link 2</a>
VII.Vulnerability Status
* Vulnerability discovered on 2006-01-12.
* Vendor notified on 2006-01-12.
* No response from vendor, vulnerability published on 2006-01-28.
VIII.Workarounds
* No vendor-supplied patch is currently available.
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Microsoft Device IO Control wrapped by the iphlpapi.dll API shipping with Windows Vista 32 bit and 64 bit contains a possibly exploitable, buffer overflow corrupting kernel memory.