* Nameko Webmail XSS Vulnerability on version <= 0.10.146 * ======================================================== * * Homepage: http://www.wizshelf.org/nameko/ * Discovered by: Andrea Menin (base64 @: bWVuaW4uYW5kcmVhQGdtYWlsLmNvbQ==) * Follow me: http://www.linkedin.com/in/andreamenin * * ======================================================== Introduction: ------------- Nameko is a set of tools for working with e-mails in PHP. The core of Nameko is composed by a set of classes for retrieve mail from a POP3 server, and parsing them to get the body (both in plain text and HTML, if included) and the attachments. Is included the NamekoWebmail, that is a powerful webmail. Description: ------------ The XSS vulnerability is located on the credits page, where is possible to change the font size by an http get request (ex. fontsize=11). The "fontsize" variable write his content inside a