Winmail Server Multiple HTML Injection Vulnerabilities
The information has been provided by Zhao Liang.
* Winmail Server 5.0 Build 0620
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
Published: October 24 2012