Description
|
|
Two vulnerabilities were identified in Rockliffe MailSite, which could be exploited by remote attackers to execute arbitrary scripting code or cause a denial of service.
The first issue is due to an input validation error in the HTTP Mail Management Agent (CGI-BIN/WCONSOLE.DLL) that does not properly handle specially crafted parameters, which could be exploited by remote attackers to crash a vulnerable application.
The second flaw is due to an input validation error in the HTTP Mail Management Agent (CGI-BIN/WCONSOLE.DLL) that does not properly handle specially crafted parameters, which could be exploited by remote attackers to cause malicious scripting code to be executed by the user's browser in the security context of an affected Web site.
|