Winmail Server 4.2 Reflected XSS (Cross-site Scripting) Web Application 0-Day Security Bug
Exploit Title: Winmail Server badlogin.php &lid parameter Reflected XSS Web Security Vulnerability
Product: Winmail Server
Vendor: Winmail Server
Vulnerable Versions: 4.2 4.1
Tested Version: 4.2 4.1
Advisory Publication: August 24, 2015
Latest Update: August 30, 2015
Vulnerability Type: Cross-Site Scripting [CWE-79]
CVE Reference:
Impact CVSS Severity (version 2.0):
CVSS v2 Base Score: 4.3 (MEDIUM) (AV:N/AC:M/Au:N/C:N/I:P/A:N) (legend)
Impact Subscore: 2.9
Exploitability Subscore: 8.6
CVSS Version 2 Metrics:
Access Vector: Network exploitable; Victim must voluntarily interact with attack mechanism
Access Complexity: Medium
Authentication: Not required to exploit
Impact Type: Allows unauthorized modification
Discover
and Reporter: Wang Jing [School of Physical and Mathematical Sciences
(SPMS), Nanyang Technological University (NTU), Singapore] (@justqdjing)
Caution Details:
(1) Vendor & Product Description:
Vendor:
Winmail Server
Product & Vulnerable Versions:
Winmail Server
4.2 4.1
Vendor URL & Download:
Product can be obtained from here,
Product Introduction Overview:
"Winmail
Server is an enterprise class mail server software system offering a
robust feature set, including extensive security measures. Winmail
Server supports SMTP, POP3, IMAP, Webmail, LDAP, multiple domains, SMTP
authentication, spam protection, anti-virus protection, SSL security,
Network Storage, remote access, Web-based administration, and a wide
array of standard email options such as filtering, signatures, real-time
monitoring, archiving, and public email folders. Winmail Server can be
configured as a mail server or gateway for ISDN, ADSL, FTTB and cable
modem networks, beyond standard LAN and Internet mail server
configurations."
(2) Vulnerability Details:
Winmail
Server web application has a computer security problem. Hackers can
exploit it by reflected XSS cyber attacks. This may allow a remote
attacker to create a specially crafted request that would execute
arbitrary script code in a user's browser session within the trust
relationship between their browser and the server.
Several other similar products 0-day vulnerabilities have been found by some other bug hunter researchers before. Winmail Server has patched some of them. "scip AG was founded in 2002. We are driven by innovation, sustainability, transparency, and enjoyment of our work. We are completely self-funded and are thus in the comfortable position to provide completely independent and neutral services. Our staff consists of highly specialized experts who focus on the topic information security and continuously further their expertise through advanced training". Scip has recorded similar XSS bugs, such as scipID 26980.
(2.1) The code flaw occurs at "&lid" parameter in "badlogin.php" page. In fact, CVE-2005-3692 mentions that "&retid" parameter in "badlogin.php" page is vulnerable to XSS attacks. But it does not mention "&lid" parameter". The scipID of the bug is 26980. Bugtraq (SecurityFocus) ID is 15493. OSVDB ID is 20926.
References:
http://seclists.org/oss-sec/2015/q3/459
http://www.tetraph.com/security/xss-vulnerability/winmail-server-4-2-reflected-xss/
http://computerobsess.blogspot.com/2015/08/winmail-xss.html
http://marc.info/?l=oss-security&m=144094251309925&w=4
http://permalink.gmane.org/gmane.comp.security.oss.general/17656
https://webtechwire.wordpress.com/2015/08/31/winmail-xss/
http://tetraph.blog.163.com/blog/static/234603051201573115638385/
http://webtechhut.blogspot.com/2015/08/winmail-xss-0day.html
http://ittechnology.lofter.com/post/1cfbf60d_806df2e
http://www.inzeed.com/kaleidoscope/xss-vulnerability/fc2-blog-xss/
http://webcabinet.tumblr.com/post/128010125747/winmail-xss-bug
http://www.openwall.com/lists/oss-security/2015/08/30/3
https://progressive-comp.com/?l=oss-security&m=144094251309925&w=1