vendor:
GWebmail
by:
Shai rod
9,3
CVSS
HIGH
XSS, DOM XSS, Flash XSS, Self XSS, Post Auth Local File Inclusion
79, 79, 79, 79, 94, 94, 94
CWE
Product Name: GWebmail
Affected Version From: 0.7.3
Affected Version To: 0.7.3
Patch Exists: YES
Related CWE: N/A
CPE: a:gwebmail:gwebmail:0.7.3
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
XSS & LFI RCE Vulnerabilities in GWebmail
Gwebmail is an ajax powered webmail system with an interface similar to Gmail. It is vulnerable to XSS in the search field, DOM XSS, Flash XSS (Vulnerable SWFUpload version), Stored XSS in E-mail Subject, Stored XSS in Display Name and contacts display name, and Post Auth Local File Inclusion.
Mitigation:
Input validation, sanitization, and output encoding should be used to prevent XSS. Access control should be used to prevent unauthorized access to sensitive files.