Nessus Plugin #12263

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

IMP Content-Type XSS Vulnerability

Family:
CGI abuses : XSS
Category:
infos
Copyright:
This script is Copyright (C) 2004 George A. Theall
Summary:
Checks for Content-Type XSS Vulnerability in IMP
Version:
$Revision: 1.8 $
Cve_id:
CAN-2004-0584
Bugtraq_id:
10501
Xrefs:
GLSA:GLSA-200406-11
Description:

The remote server is running at least one instance of IMP whose version
number is between 2.0 and 3.2.3 inclusive. Such versions are vulnerable
to a cross-scripting attack whereby an attacker may be able to cause a
victim to unknowingly run arbitrary Javascript code simply by reading a
MIME message with a specially crafted Content-Type header.

For information about the vulnerability, including exploits, see :

- http://www.rs-labs.com/adv/RS-Labs-Advisory-2004-2.txt
- http://www.rs-labs.com/adv/RS-Labs-Advisory-2004-1.txt

Note : Nessus has determined the vulnerability exists on the target
simply by looking at the version number of IMP installed there
it has
not attempted to actually exploit the vulnerability.

Solution : Upgrade to IMP version 3.2.4 or later.
Risk factor : High
Generiert am 27.04.2005 um 18:49:54 Uhr.