Hoyt LLC Research investigates and reports on security vulnerabilities embedded in Web Applications and Products used in wide-scale deployment.

Report generated by xss.cx at Mon Mar 14 12:12:34 CDT 2011.

XSS.CX Home | SmarterStats 6.0 Full Disclosure | Blog repost on Stored XSS in SmarterMail 8.0.4086.25048
Loading


Hoyt LLC Research | Boston, MA US | 1-9-2011

Published Vulnerabilities

National Vulnerability Database Publications

NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. NVD includes databases of security checklists, security related software flaws, misconfigurations, product names, and impact metrics.

CVE-2010-3486 | URI http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-3486

CVE-2010-3425 | URI http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-3425

Common Vulnerability Enumeration Publications

CVE® International in scope and free for public use, CVE is a dictionary of publicly known information security vulnerabilities and exposures. CVE’s common identifiers enable data exchange between security products and provide a baseline index point for evaluating coverage of tools and services.

CVE-2010-3486 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3486

CVE-2010-3425 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3425

Full Disclosure

SmarterMail 7.0, 7.1, 7.2, 7.3, 7.4, 8.0.4086.25048

SmarterMail delivers Exchange-level email server software features for a fraction of the cost. With lower hardware requirements, superior stability and reduced maintenance costs, SmarterMail has significantly lower Total Cost of Ownership (TCO) and is the best-in-class Microsoft Exchange alternative for businesses and hosting companies.

SmarterStats 5.x, 6.x

Powerful enough to handle the requirements of large enterprises, yet cost-effective enough to remain accessible to individual website owners, SmarterStats provides the website statistics businesses need to increase conversions and maximize ROI.

Exploit References

Secunia 41765, OSVDB 68624, OSVDB 68623, EDB 15313, OSVDB 68367, OSVDB 68368, OSVDB 68369, OSVDB 68195, OSVDB 68137, OSVDB 69138, OSVDB 69139, OSVDB 68140.

Plesk Small Business Manager for Windows Version 10.2.0

Exploit References

References from OSVDB 68623 and OSVDB 68624

References from Secunia: SA41677, SA41485, Secunia 41765, References from Exploit-DB Links: EDB 15313, EDB 15189, EDB 15185, EDB 15048.