VeriSign, Inc.® US Home | Worldwide Sites | Site Map

CommuniGate Pro WebMail Cross-Site Scripting Vulnerability


I. BACKGROUND

CommuniGate Pro (http://www.stalker.com/CommuniGatePro/) is a highly
scalable Internet Mail server with various features, including webmail.

II. DESCRIPTION

CommuniGate Pro's webmail subsystem attempts to remove potentially
malicious tags from HTML emails before displaying them. However,
flaws in the HTML parsing logic allow this cleanup to be bypassed.

The following (in an email with a content-type of text/html) slips
the <script> tags through and causes javascript popups when the
email is viewed via WebMail:

  <_sdf foo="<script>alert(1)</script> ">
  <hr>
  <s"f f="ad    <foo bar=" > <script>alert(2)</script> "> 

III. ANALYSIS

This vulnerability makes it possible to construct a malicious email
which, when viewed via webmail, performs malicious actions such as
forwarding copies of the victim's saved email to the attacker's
remote mailbox.

IV. DETECTION

This issue was patched in CommuniGate Pro version 4.1b5. All versions
prior to version 4.1b5 are vulnerable.

V. WORKAROUND

iDEFENSE is currently unaware of any workarounds for this issue.

VI. VENDOR RESPONSE

The vendor addressed this issue in version 4.1b5 of CommuniGate Pro.

VII. CVE INFORMATION

A Mitre Corp. Common Vulnerabilities and Exposures (CVE) number has not
been assigned yet.

VIII. DISCLOSURE TIMELINE

02/25/2003 Exploit acquired by iDEFENSE
04/30/2003 Vendor patched issue in version 4.1b5

IX. CREDIT

Nick Cleaton (nick [at] cleaton.net) is credited with discovering this
vulnerability.

Get paid for vulnerability research
http://www.idefense.com/poi/teams/vcp.jsp

X. LEGAL NOTICES

Copyright 2004 iDEFENSE, Inc.

Permission is granted for the redistribution of this alert
electronically. It may not be edited in any way without the express
written consent of iDEFENSE. If you wish to reprint the whole or any
part of this alert in any other medium other than electronically, please
email customerservice@idefense.com for permission.

Disclaimer: The information in the advisory is believed to be accurate
at the time of publishing based on currently available information. Use
of the information constitutes acceptance for use in an AS IS condition.
There are no warranties with regard to this information. Neither the
author nor the publisher accepts any liability for any direct, indirect,
or consequential loss or damage arising from use of, or reliance on,
this information.



Need more information?
Speak with a service representative at 650-426-5310 Request information online


Contact Us
Please contact sales at
650-426-5310 or
submit your inquiry online.


US Home  :  Worldwide Sites  :  Site Map  :  Search
VeriSign (Nasdaq: VRSN) operates intelligent infrastructure services that enable and protect billions of interactions across the world's voice and data networks. VeriSign offerings include SSL Certificates, two-factor authentication, identity protection, managed network security, public key infrastructure (PKI), security consulting, information management, as well as solutions for intelligent communications, commerce, and content. VeriSign is also building next-generation service offerings for emerging opportunities such as RFID-enabled supply chains, VoIP technology, and digital-content distribution over mobile and broadband networks.