HTTP: IMG tag in URL with Javascript Cross-Side Scripting

This signature detects HTML <img> tags in URLs that include Javascript. Because <img> tags should never be present in URLs, the presence of Javascript in such a URL is a clear indication of a Cross-Side Scripting (XSS) attack. XSS attacks are typically Web browser-independent.

Extended Description

The webmail package embedded in Merak Mail Server is reported prone to multiple vulnerabilities. The vulnerabilities reported are: - Multiple cross-site scripting vulnerabilities - An HTML injection vulnerability - A PHP source code disclosure vulnerability - An SQL injection vulnerability These vulnerabilities are reported to exist in versions prior to 7.5.2.

Affected Products

Merak webmail_server

Short Name
HTTP:XSS:URL-IMG-XSS
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2004-1719 CVE-2009-1968 Cross-Side IMG Javascript Scripting URL bid:10966 in tag with
Release Date
07/01/2004
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3725
False Positive
Unknown
Vendors

Merak

CVSS Score

4.3

Found a potential security threat?