Public Vulnerability Reports

CommuniGate Pro WebMail Cross-Site Scripting Vulnerability



CommuniGate Pro ( is a highly
scalable Internet Mail server with various features, including webmail.


CommuniGate Pro's webmail subsystem attempts to remove potentially
malicious tags from HTML emails before displaying them. However,
flaws in the HTML parsing logic allow this cleanup to be bypassed.

The following (in an email with a content-type of text/html) slips
the <script> tags through and causes javascript popups when the
email is viewed via WebMail:

  <_sdf foo="<script>alert(1)</script> ">
  <s"f f="ad    <foo bar=" > <script>alert(2)</script> "> 


This vulnerability makes it possible to construct a malicious email
which, when viewed via webmail, performs malicious actions such as
forwarding copies of the victim's saved email to the attacker's
remote mailbox.


This issue was patched in CommuniGate Pro version 4.1b5. All versions
prior to version 4.1b5 are vulnerable.


iDEFENSE is currently unaware of any workarounds for this issue.


The vendor addressed this issue in version 4.1b5 of CommuniGate Pro.


A Mitre Corp. Common Vulnerabilities and Exposures (CVE) number has not
been assigned yet.


02/25/2003 Exploit acquired by iDEFENSE
04/30/2003 Vendor patched issue in version 4.1b5


Nick Cleaton (nick [at] is credited with discovering this

Get paid for vulnerability research


Copyright © 2004 Verisign, Inc.

Permission is granted for the redistribution of this alert
electronically. It may not be edited in any way without the express
written consent of iDEFENSE. If you wish to reprint the whole or any
part of this alert in any other medium other than electronically, please
email for permission.

Disclaimer: The information in the advisory is believed to be accurate
at the time of publishing based on currently available information. Use
of the information constitutes acceptance for use in an AS IS condition.
There are no warranties with regard to this information. Neither the
author nor the publisher accepts any liability for any direct, indirect,
or consequential loss or damage arising from use of, or reliance on,
this information.