source: http://www.securityfocus.com/bid/4740/info NOCC is a web based email client implemented in PHP4. It includes support for POP3, SMTP and IMAP servers, MIME attachments and multiple languages. A script injection issue has been reported with the way emails are displayed to users of NOCC webmail. A malicious attacker can include script code in an email and potentially get full access to a victim's mailbox. <script>alert(document.cookie)</script> This will show the victim's session id.
Related ExploitsTrying to match CVEs (1): CVE-2002-2343
Trying to match OSVDBs (1): 58969
Other Possible E-DB Search Terms: NOCC 0.9.x, NOCC