Mozilla Thunderbird vulnerability allows hackers to Insert malicious code into Emails
Jan 28, 2014
    Do you use Thunderbird , a free; open-source; cross-platform application for managing email and news feeds? According to a Pakistani Security Researcher from Vulnerability-Lab,  a flaw gives an attacker the ability to run code on a user's machine.   Mozilla  Thunderbird 17.0.6 email application is vulnerable to critical validation and filter bypass vulnerability, enables an attacker to bypass the filter that prevents HTML tags from being used in messages.    According to a Security Advisory  released by Vulnerability-Lab , the flaw resides in Mozilla's Gecko engine. During the testing, the researchers found many java script errors which  gave the researcher much hope in believing that the application might  actually be vulnerable.    By default, HTML tags like <script>  and <iframe>   are blocked in Thunderbird and get filtered immediately upon insertion.  However, while drafting a new email message, attackers can easily  bypass the current input filters by encoding...