Vulnerabilities > CVE-2006-0978 - HTML Injection vulnerability in Argosoft Mail Server 1.8.8.5
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE Summary
Multiple cross-site scripting (XSS) vulnerabilities in the View Headers (aka viewheaders) functionality in ArGoSoft Mail Server Pro 1.8.8.5 allow remote attackers to inject arbitrary web script or HTML via (1) the Subject header, (2) the From header, and (3) certain other unspecified headers. This vulnerability affects ArGoSoft, Mail Server Pro version 1.8.8.5, and may affect all previous versions.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | CGI abuses : XSS |
NASL id | ARGOSOFT_MS_WEBMAIL_XSS.NASL |
description | The remote host is running ArGoSoft Mail Server Pro, a messaging system for Windows. According to its banner, the webmail server bundled with the version of ArGoSoft Mail Server Pro installed on the remote host fails to properly filter message headers before displaying them as part of a message to users. A remote attacker may be able to exploit this issue to inject arbitrary HTML and script code into a user |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 20985 |
published | 2006-02-28 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/20985 |
title | ArGoSoft Mail Server Pro Webmail viewheaders Multiple Field XSS |
code |
|
References
- http://secunia.com/advisories/18991
- http://secunia.com/secunia_research/2006-6/advisory/
- http://securityreason.com/securityalert/504
- http://www.osvdb.org/23512
- http://www.securityfocus.com/archive/1/426206/100/0/threaded
- http://www.securityfocus.com/bid/16834
- http://www.vupen.com/english/advisories/2006/0751
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24945