PHPGroupWare Wiki Cross-Site Scripting Vulnerability
BID:11130
Info
PHPGroupWare Wiki Cross-Site Scripting Vulnerability
| Bugtraq ID: | 11130 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-0875 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 07 2004 12:00AM |
| Updated: | Jul 12 2009 07:06AM |
| Credit: | This vulnerability was reported by the vendor. |
| Vulnerable: |
PHPGroupWare PHPGroupWare 0.9.16 RC1 PHPGroupWare PHPGroupWare 0.9.16 .002 PHPGroupWare PHPGroupWare 0.9.16 .000 PHPGroupWare PHPGroupWare 0.9.14 .007 PHPGroupWare PHPGroupWare 0.9.14 .006 PHPGroupWare PHPGroupWare 0.9.14 .005 PHPGroupWare PHPGroupWare 0.9.14 .003 PHPGroupWare PHPGroupWare 0.9.13 PHPGroupWare PHPGroupWare 0.9.12 |
| Not Vulnerable: |
PHPGroupWare PHPGroupWare 0.9.16 .003 |
Discussion
PHPGroupWare Wiki Cross-Site Scripting Vulnerability
It is reported that PHPGroupWare is affected by a cross-site scripting vulnerability in its wiki application. This issue is due to a failure of the application to properly sanitize user-supplied URI input.
This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were to be followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.
This vulnerability is reported to exist in versions prior to 0.9.16.003 of PHPGroupWare.
It is reported that PHPGroupWare is affected by a cross-site scripting vulnerability in its wiki application. This issue is due to a failure of the application to properly sanitize user-supplied URI input.
This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were to be followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.
This vulnerability is reported to exist in versions prior to 0.9.16.003 of PHPGroupWare.
Exploit / POC
PHPGroupWare Wiki Cross-Site Scripting Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
PHPGroupWare Wiki Cross-Site Scripting Vulnerability
Solution:
Gentoo has released updates that may be applied with the following commands:
emerge sync
emerge -pv ">=www-apps/phpgroupware-0.9.16.003"
emerge ">=www-apps/phpgroupware-0.9.16.003"
The vendor has released version 0.9.16.003 addressing this issue:
PHPGroupWare PHPGroupWare 0.9.12
PHPGroupWare PHPGroupWare 0.9.13
PHPGroupWare PHPGroupWare 0.9.14 .006
PHPGroupWare PHPGroupWare 0.9.14 .005
PHPGroupWare PHPGroupWare 0.9.14 .003
PHPGroupWare PHPGroupWare 0.9.14 .007
PHPGroupWare PHPGroupWare 0.9.16 RC1
PHPGroupWare PHPGroupWare 0.9.16 .000
PHPGroupWare PHPGroupWare 0.9.16 .002
Solution:
Gentoo has released updates that may be applied with the following commands:
emerge sync
emerge -pv ">=www-apps/phpgroupware-0.9.16.003"
emerge ">=www-apps/phpgroupware-0.9.16.003"
The vendor has released version 0.9.16.003 addressing this issue:
PHPGroupWare PHPGroupWare 0.9.12
-
PHPGroupWare phpgroupware-0.9.16.003.tar.gz
http://downloads.phpgroupware.org/files/0.9.16-release/phpgroupware-0. 9.16.003.tar.gz
PHPGroupWare PHPGroupWare 0.9.13
-
PHPGroupWare phpgroupware-0.9.16.003.tar.gz
http://downloads.phpgroupware.org/files/0.9.16-release/phpgroupware-0. 9.16.003.tar.gz
PHPGroupWare PHPGroupWare 0.9.14 .006
-
PHPGroupWare phpgroupware-0.9.16.003.tar.gz
http://downloads.phpgroupware.org/files/0.9.16-release/phpgroupware-0. 9.16.003.tar.gz
PHPGroupWare PHPGroupWare 0.9.14 .005
-
PHPGroupWare phpgroupware-0.9.16.003.tar.gz
http://downloads.phpgroupware.org/files/0.9.16-release/phpgroupware-0. 9.16.003.tar.gz
PHPGroupWare PHPGroupWare 0.9.14 .003
-
PHPGroupWare phpgroupware-0.9.16.003.tar.gz
http://downloads.phpgroupware.org/files/0.9.16-release/phpgroupware-0. 9.16.003.tar.gz
PHPGroupWare PHPGroupWare 0.9.14 .007
-
PHPGroupWare phpgroupware-0.9.16.003.tar.gz
http://downloads.phpgroupware.org/files/0.9.16-release/phpgroupware-0. 9.16.003.tar.gz
PHPGroupWare PHPGroupWare 0.9.16 RC1
-
PHPGroupWare phpgroupware-0.9.16.003.tar.gz
http://downloads.phpgroupware.org/files/0.9.16-release/phpgroupware-0. 9.16.003.tar.gz
PHPGroupWare PHPGroupWare 0.9.16 .000
-
PHPGroupWare phpgroupware-0.9.16.003.tar.gz
http://downloads.phpgroupware.org/files/0.9.16-release/phpgroupware-0. 9.16.003.tar.gz
PHPGroupWare PHPGroupWare 0.9.16 .002
-
PHPGroupWare phpgroupware-0.9.16.003.tar.gz
http://downloads.phpgroupware.org/files/0.9.16-release/phpgroupware-0. 9.16.003.tar.gz
References
PHPGroupWare Wiki Cross-Site Scripting Vulnerability
References:
References:
- Changelog (PHPGroupWare)
- PHPGroupWare Homepage (PHPGroupWare)