vendor:
Hexamail Server
by:
modpr0be[at]Spentera, @modpr0be
8,8
CVSS
HIGH
Persistent XSS
79
CWE
Product Name: Hexamail Server
Affected Version From: 4.4.5
Affected Version To: 4.4.5
Patch Exists: NO
Related CWE: N/A
CPE: a:hexamail:hexamail_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3, Windows 2003 SP2, Windows 7 SP1, Chrome 19.0.x, IE9, Safari 5.1.7
2012
Hexamail Server <= 4.4.5 Persistent XSS Vulnerability
Hexamail Server suffers persistent XSS vulnerability in the mail body, allowing malicious user to execute scripts in a victim’s browser to hijack user sessions, redirect users, and or hijack the user’s browser. By sending a malicious script to the victim email, the webmail automatically load the mail body, so the script will be automatically executed without permission from user.
Mitigation:
Not available.