vendor:
IMail Server
by:
DaOne aka Mocking Bird
7,5
CVSS
HIGH
Cross-Site Scripting (XSS)
79
CWE
Product Name: IMail Server
Affected Version From: 11.01
Affected Version To: 11.01
Patch Exists: NO
Related CWE: N/A
CPE: 2.3:a:ipswitch:imail_server:11.01
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2013
Ipswitch IMail 11.01 XSS Vulnerability
This exploit uses a malicious script to send an email to a victim with an XSS payload. The payload is executed when the victim opens the email, allowing the attacker to access the victim's cookies.
Mitigation:
Input validation and output encoding can be used to prevent XSS attacks.