[UNIX] SqWebMail Conditional Comments Script Insertion

SecuriTeam <[email protected]> 7 Sep 2005 11:08:37 +0200
Newsgroups gmane.comp.security.securiteam
Message-ID <[email protected]>
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html 

- - - - - - - - -



  SqWebMail Conditional Comments Script Insertion
------------------------------------------------------------------------


SUMMARY

Secunia Research has discovered a vulnerability in SqWebMail, which can be 
exploited by malicious people to conduct script insertion attacks.

DETAILS

Vulnerable Systems:
 * SqWebMail version 5.0.4

The vulnerability is caused due to SqWebMail allowing usage of e.g. the 
"<script>" tag within an HTML comment. This, combined with "Conditional 
Comments" in Internet Explorer, can be exploited to execute arbitrary 
script code in a user's browser session in context of a vulnerable site 
when a malicious email is viewed.

Successful exploitation requires that the user is using Internet Explorer.

Example in an HTML email:
<!--[if IE]>
<script>alert("Vulnerable!");</script>
<![endif]-->

Solution:
The vendor has issued an updated version of SqWebMail, which fixes this 
vulnerability:  <http://www.courier-mta.org/?download.php> 
http://www.courier-mta.org/?download.php.

Disclosure Timeline:
05/09/2005 - Initial vendor notification
05/09/2005 - Vendor confirms vulnerability and releases a fix
06/09/2005 - Public disclosure


ADDITIONAL INFORMATION

The information has been provided by  <mailto:[email protected]> Secunia 
Research.
The original article can be found at:  
<http://secunia.com/secunia_research/2005-44/advisory/> 
http://secunia.com/secunia_research/2005-44/advisory/



======================================== 


This bulletin is sent to members of the SecuriTeam mailing list. 
To unsubscribe from the list, send mail with an empty subject line and body to: [email protected] 
In order to subscribe to the mailing list, simply forward this email to: [email protected] 


==================== 
==================== 

DISCLAIMER: 
The information in this bulletin is provided "AS IS" without warranty of any kind. 
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.