Sqwebmail Http Splitting vuln
[Hackers Center Security Group] Sqwebmail Http Splitting Vulnerability

Hackers Center Security Group 
Zinho's Security Advisory         

Desc: Http Splitting leads to email account stealing 
Product: SQWebmail 
Risk: High 

A dangerous http splitting attack can be taken against mailboxes that  use Sqwebmail as web mail interface. Anyone can send a malformed  link in the email body and stealing session cookie and passwords. 

Proof of concept:  
sqwebmail?redirect=%0d%0a%0d%0a[INJECT SCRIPT] 


Vendor should patch this issue soon as anyone can attack a user  directly. 

zinho-no-spam @        

