Cross-site scripting (XSS) vulnerability in Open WebMail 2.x allows remote attackers to inject arbitrary HTML or web script via the domain name parameter (logindomain) in the login page.
https://exchange.xforce.ibmcloud.com/vulnerabilities/19335
http://www.securityfocus.com/bid/12547
http://turtle.ee.ncku.edu.tw/openwebmail/download/cert/patches/SA-05:01/2.5x.patch
http://turtle.ee.ncku.edu.tw/openwebmail/doc/changes.txt