[NEWS] Caramail Cross-Site Scripting Vulnerability
From: support@securiteam.comDate: 12/27/01
- Previous message: support@securiteam.com: "[UNIX] Linux Package Default UID (573)"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: support@securiteam.com To: list@securiteam.com Date: Thu, 27 Dec 2001 07:37:55 +0100 (CET)
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -
Caramail Cross-Site Scripting Vulnerability
------------------------------------------------------------------------
SUMMARY
<http://www.Caramail.com> Caramail, a French web-based e-mail service,
contains a vulnerability that allows attackers launch a CSS (Cross Site
Scripting) attack. This in turn would allow them to send victims a special
URL that will show information as if it were coming from the website.
DETAILS