Title: 1st Class Internet Solutions 1st Class Mail Server Multiple Input Validation Vulnerabilities
Severity: MODERATE
Description:
1st Class Mail Server is an email/web mail server solution developed and maintained by 1st Class Internet Solutions.
Multiple vulnerabilities have been identified in the application that may allow a remote attacker to carry out directory traversal and cross-site scripting attacks.
The following specific issues have been reported:
It has been reported that the application is prone to multiple cross-site scripting issue in various modules and parameters. Specifically, the 'MessageIndex' parameter of 'viewmail.tagz', and the 'Mailbox' parameter of various scripts such as 'members.tagz', 'general.tagz', 'advanced.tagz', and 'list.tagz' are vulnerable to these issues. The issues present themselves due to insufficient sanitization of user-supplied data. User-supplied input may be included in dynamically generated pages. A successful attack may be carried out by an attacker creating a malicious link to a vulnerable site that includes hostile HTML and script code. This code may be rendered in the browser of a victim user who visits the malicious link and this will occur in the security context of the site hosting the software.
An unspecified directory traversal vulnerability has been identified in the application as well. This issue is due to a failure of the application to properly filter user supplied URI requests. A malicious user could leverage this issue by requesting files outside of the web-server root directory with directory traversal strings such as '../'. This would allow a successful attacker to view arbitrary files that are readable by the web-server process. Information acquired by exploiting this issue may be used to aid further attacks against a vulnerable system.
1st Class Mail Server version 4.01 is reported to be prone to these issues, however, it is possible that other versions are affected as well.
Affected Products:
- 1st Class Internet Solutions 1st Class Mail Server 4.0.01
References:
- 1st Class Internet Solutions: 1st Class Mail Server Homepage
- Dr_Insane: 1st Class mail server 4.01 Directory Traversal and XSS vulnerabilities
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.