Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: Webmails + Internet Explorer can create unwanted javascript execution
From: Jedi/Sector One <j () pureftpd org>
Date: Fri, 3 Oct 2003 21:16:34 +0200

On Fri, Oct 03, 2003 at 11:56:47AM -0500, Jason Munro wrote:
While squirrelmail's filter is based on the same engine apparently either
it's not up to date or the params are not set as tight.

  It looks like Squirrelmail 1.4.0 doesn't filter it, while 1.4.2 does.
  
  Upgrading Squirrelmail is not a bad idea anyway, as before version 1.4.1, 
external images could be loaded through the "lowsrc" attribute on browsers
that handle it. But this was not a bug in Squirrelmail either, just a
combination to avoid.


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]