JawMail executes Javascript code that is contained in the name of the sender of an email.
An example for the sender field:
"alert('ouch');"
I have not checked the CC and BCC fields, but I suspect they are vulnerable as well.
Also, I noticed a problem with the way in which the body of an email is formatted. JawMail automatically...
2007-09-09 13:02:29 UTC in Just Another Web Mail