Winmail Server Multiple HTML Injection Vulnerabilities

Summary

Winmail Server is prone to multiple HTML-injection vulnerabilities because the application fails to properly sanitize user-supplied input.

Credit:

The information has been provided by Zhao Liang.


Details

Vulnerable Systems:
 * Winmail Server 5.0 Build 0620

Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.

Disclosure Timeline:
Published: October 24 2012

Categories: News