Horde IMP HTML+TIME HTML Injection Vulnerability
BID:10845
Info
Horde IMP HTML+TIME HTML Injection Vulnerability
| Bugtraq ID: | 10845 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 03 2004 12:00AM |
| Updated: | Aug 03 2004 12:00AM |
| Credit: | The individual responsible for the discovery of this issue is currently unknown; the vendor disclosed this issue. |
| Vulnerable: |
Horde Project IMP 3.2.4 Horde Project IMP 3.2.3 Horde Project IMP 3.2.2 Horde Project IMP 3.2.1 Horde Project IMP 3.2 Horde Project IMP 3.1.2 Horde Project IMP 3.1 Horde Project IMP 3.0 Gentoo Linux 1.4 _rc3 Gentoo Linux 1.4 _rc2 Gentoo Linux 1.4 _rc1 Gentoo Linux 1.4 Gentoo Linux 1.2 Gentoo Linux 1.1 a Gentoo Linux 0.7 Gentoo Linux 0.5 |
| Not Vulnerable: |
Horde Project IMP 3.2.5 |
Discussion
Horde IMP HTML+TIME HTML Injection Vulnerability
Reportedly Horde IMP is affected by an HTML injection vulnerability due to insufficient sanitization of HTML+TIME script.
An attacker can exploit this issue to gain access to an unsuspecting user's cookie based authentication credentials; disclosure of personal email is possible. Other attacks are also possible.
Reportedly Horde IMP is affected by an HTML injection vulnerability due to insufficient sanitization of HTML+TIME script.
An attacker can exploit this issue to gain access to an unsuspecting user's cookie based authentication credentials; disclosure of personal email is possible. Other attacks are also possible.
Exploit / POC
Horde IMP HTML+TIME HTML Injection Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
Horde IMP HTML+TIME HTML Injection Vulnerability
Solution:
The vendor has released an upgrade dealing with this issue.
Gentoo has released an advisory (GLSA 200408-07) to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge sync
emerge -pv ">=horde-imp-3.2.5"
emerge ">=horde-imp-3.2.5"
Horde Project IMP 3.0
Horde Project IMP 3.1
Horde Project IMP 3.1.2
Horde Project IMP 3.2
Horde Project IMP 3.2.1
Horde Project IMP 3.2.2
Horde Project IMP 3.2.3
Horde Project IMP 3.2.4
Solution:
The vendor has released an upgrade dealing with this issue.
Gentoo has released an advisory (GLSA 200408-07) to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge sync
emerge -pv ">=horde-imp-3.2.5"
emerge ">=horde-imp-3.2.5"
Horde Project IMP 3.0
-
Horde imp-3.2.5.tar.gz
ftp://ftp.horde.org/pub/imp/imp-3.2.5.tar.gz
Horde Project IMP 3.1
-
Horde imp-3.2.5.tar.gz
ftp://ftp.horde.org/pub/imp/imp-3.2.5.tar.gz
Horde Project IMP 3.1.2
-
Horde imp-3.2.5.tar.gz
ftp://ftp.horde.org/pub/imp/imp-3.2.5.tar.gz
Horde Project IMP 3.2
-
Horde imp-3.2.5.tar.gz
ftp://ftp.horde.org/pub/imp/imp-3.2.5.tar.gz
Horde Project IMP 3.2.1
-
Horde imp-3.2.5.tar.gz
ftp://ftp.horde.org/pub/imp/imp-3.2.5.tar.gz
Horde Project IMP 3.2.2
-
Horde imp-3.2.5.tar.gz
ftp://ftp.horde.org/pub/imp/imp-3.2.5.tar.gz
Horde Project IMP 3.2.3
-
Horde imp-3.2.5.tar.gz
ftp://ftp.horde.org/pub/imp/imp-3.2.5.tar.gz
Horde Project IMP 3.2.4
-
Horde imp-3.2.5.tar.gz
ftp://ftp.horde.org/pub/imp/imp-3.2.5.tar.gz
References
Horde IMP HTML+TIME HTML Injection Vulnerability
References:
References:
- Diff for imp/docs/CHANGES between version 1.389.2.106 and 1.389.2.109 (Horde.org)
- IMP Homepage (Horde.org)