19-05-2011
MDaemon WorldClient Email Subject Script Insertion Vulnerability
Input passed via the email subject is not properly sanitised before being used in the WorldClient Summary page. This can be exploited to insert arbitrary HTML and script code, which will be executed in a user's browser session in context of an affected site when the malicious data is being viewed.

Details



back