Vulnerability Information: - EDB-ID: 20357 - CVE: 2012-2584 - Author: LONEFERRET - Type: WEBAPPS - Platform: WINDOWS - Date: 2012-08-08 - Vulnerable App: Alt-N MDaemon Free 12.5.4 Timeline: - 29 May 2012: Vulnerability reported to CERT - 30 May 2012: Response received from CERT with disclosure date set to 20 Jul 2012 - 18 Jul 2012: Vendor requests additional information from CERT. CERT advises vendor to contact the researcher. - 08 Aug 2012: Public Disclosure Affected Systems: - Installed On: Windows Server 2003 SP2 - Client Test OS: Windows XP Pro SP3 (x86) - Browser Used: Internet Explorer 8 Vulnerability Details: - Injection Point: Body - Injection Payload(s): 1. 2. 3. Exploit Code: - Python script for sending email containing the XSS payload