CVE-2005-3692 Information

Description

Cross-site scripting (XSS) vulnerability in AMAX Magic Winmail Server 4.2 (build 0824) and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) retid parameter in badlogin.php (2) Content-Type headers in HTML mails and (3) HTML mail attachments.

Reference

http://archives.neohapsis.com/archives/fulldisclosure/2005-11/0580.html http://secunia.com/advisories/16665 http://secunia.com/secunia_research/2005-58/advisory/ http://www.osvdb.org/20926 http://www.osvdb.org/20927 http://www.osvdb.org/20928 http://www.securityfocus.com/bid/15493 http://www.vupen.com/english/advisories/2005/2485

Share on: