Site Archives XSS
MDaemon WorldClient Vulnerability
GSA Reference Number: AD081119-01
Updated: 11-19-2008
Simply Put: Secunia is reporting a vulnerability in MDaemon’s WorldClient webmail frontend. Attackers could send a specially-crafted email that, if viewed in the WorldClient webmail interface, could run malicious scripts or HTML code on the user’s machine without their interaction. All the user would have to do is read the email. The vendor has a patch available.
SonicWALL Content Filter Security Vulnerability
GSA Reference Number: AD081031-01
Updated: 11-3-2008
Simply Put: SonicWALL has released an advisory regarding a new vulnerability found in its content filter. If a user behind a SonicWALL with content filtering enabled clicks on a malicious link, an attacker can cause malicious javascript to be executed through the content filter’s “Blocked Traffic” screen. This vulnerability only affects SonicWALLs running the Enhanced OS using the content filter with the CFS Block Page. See below for vulnerable versions.
Advanced Phishing Advisory
GSA Reference Number: AD080116-01
Simply Put: A new phishing attack has been targeted to customers of a financial institution in Italy. This attack is unique because it links to the institution’s actual website instead of using a fake website like most phishing attacks. Once the customer clicks on the link in the email, they are directed to the institution’s website to log on. However, an attack embedded within the link allows the attacker to capture the username and password as the user logs in. The username and password are recorded by the attacker for future use.
Find It Quickly
Find what you're looking for quickly by using our keyword search. Can't find it? Try our links below.
Monthly Archives
Find posts by the month they were written.
- March 2010
- February 2010
- January 2010
- December 2009
- November 2009
- October 2009
- September 2009
- August 2009
- July 2009
- June 2009
- May 2009
- April 2009
- March 2009
- February 2009
- January 2009
- December 2008
- November 2008
- October 2008
- September 2008
- July 2008
- May 2008
- April 2008
- March 2008
- January 2008
- December 2007
- November 2007