ArGoSoft Mail Server Pro E-Mail HTML...

- AV AC AU C I A
发布: 2002-10-07
修订: 2025-04-13

The ArGoSoft Mail Server Pro web mail system does not sufficiently sanitize HTML from e-mail messages. It is possible for a remote attacker to inject arbitrary HTML and script code into e-mail messages, which will be rendered in the user's web client when the malicious message is viewed. A remote attacker could potentially exploit this condition to steal cookie-based authentication credentials from a legitimate user of the web mail system. Additionally, it has been reported that user credentials are stored in plaintext in cookies.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息