header-logo
Suggest Exploit
vendor:
AntiSpam & EMail
by:
SecurityFocus
7,5
CVSS
HIGH
Cross-Site Scripting, URI-Redirection, and HTML-Injection
79,601,602
CWE
Product Name: AntiSpam & EMail
Affected Version From: 7.3.1
Affected Version To: 7.3.1
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010

SonicWall AntiSpam & EMail Cross-Site Scripting, URI-Redirection, and HTML-Injection Vulnerabilities

SonicWall AntiSpam & EMail is prone to a cross-site scripting vulnerability, a URI-redirection vulnerability, and an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied input. Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials, control how the site is rendered to the user, or conduct phishing attacks. Other attacks are also possible.

Mitigation:

Input validation should be used to ensure that untrusted data is not used to generate unexpected results. Additionally, users should be aware of the risks associated with clicking on untrusted links.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/51337/info

SonicWall AntiSpam & EMail is prone to a cross-site scripting vulnerability, a URI-redirection vulnerability, and an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied input.

Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials, control how the site is rendered to the user, or conduct phishing attacks. Other attacks are also possible.

AntiSpam & EMail 7.3.1 is vulnerable; other versions may also be affected. 

http://www.example.com/reports_mta_queue_status.html?hostname=greenland%22%3E%3C*

http://www.example.com/msg_viewer_user_mail.html?messageStoreId=shard_20100321/256665421/JUI&direction=