Site Archives Secunia

MDaemon WorldClient Vulnerability

Posted on November 19th, 2008

GSA Reference Number: AD081119-01
Updated: 11-19-2008

Simply Put: Secunia is reporting a vulnerability in MDaemon’s WorldClient webmail frontend.  Attackers could send a specially-crafted email that, if viewed in the WorldClient webmail interface, could run malicious scripts or HTML code on the user’s machine without their interaction.  All the user would have to do is read the email.  The vendor has a patch available.