From snsadv@lac.co.jp Thu Jun 13 13:46:56 2002 From: "snsadv@lac.co.jp" To: bugtraq@securityfocus.com Date: Thu, 13 Jun 2002 14:31:43 +0900 Subject: [SNS Advisory No.54] Active! mail Executing the Script upon the Opening of a Mail Message Vulnerability ---------------------------------------------------------------------- SNS Advisory No.54 Active! mail Executing the Script upon the Opening of a Mail Message Vulnerability Problem first discovered: Fri, 31 May 2002 Published: Wed, 13 June 2002 ---------------------------------------------------------------------- Overview: --------- Active! mail displays messages without converting them properly when a specific e-mail header contains HTML tags. Problem Description: -------------------- Active! mail developed and distributed by TransWARE Co., (http://www.transware.co.jp/), is a web-based e-mail system. Active! mail displays messages without converting them properly when a specific e-mail header contains HTML tags. If for example, a user receives an e-mail embedding a malicious