eGroupWare Multiple Cross-Site Scripting and SQL Injection Vulnerabilities
BID:13212
Info
eGroupWare Multiple Cross-Site Scripting and SQL Injection Vulnerabilities
| Bugtraq ID: | 13212 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Unknown |
| Local: | Unknown |
| Published: | Apr 18 2005 12:00AM |
| Updated: | Apr 18 2005 12:00AM |
| Credit: | Discovery credited to James from GulfTech Security Research. |
| Vulnerable: |
eGroupWare eGroupWare 1.0.6 eGroupWare eGroupWare 1.0.3 eGroupWare eGroupWare 1.0.1 eGroupWare eGroupWare 1.0 |
| Not Vulnerable: |
eGroupWare eGroupWare 1.0 .0.007 |
Discussion
eGroupWare Multiple Cross-Site Scripting and SQL Injection Vulnerabilities
eGroupWare is prone to multiple input validation vulnerabilities. A fixed version is available.
The issues arise due to a failure of the application to properly validate user-supplied input. These issues result in cross-site scripting and SQL injection attacks.
eGroupWare is prone to multiple input validation vulnerabilities. A fixed version is available.
The issues arise due to a failure of the application to properly validate user-supplied input. These issues result in cross-site scripting and SQL injection attacks.
Exploit / POC
eGroupWare Multiple Cross-Site Scripting and SQL Injection Vulnerabilities
An exploit is not required. The following proof of concepts were supplied:
For the cross-site scripting issues:
http://egroupware/index.php?menuaction=addressbook.uiaddressbook.edit&ab_id=11[XSS]
http://egroupware/index.php?menuaction=manual.uimanual.view&page=ManualAddressbook[XSS]
http://egroupware/index.php?menuaction=forum.uiforum.post&type=new[XSS]
http://egroupware/wiki/index.php?page=RecentChanges[XSS]
http://egroupware/wiki/index.php?action=history&page=WikkiTikkiTavi&lang=en[XSS]
http://egroupware/index.php?menuaction=wiki.uiwiki.edit&page=setup[XSS]
http://egroupware/sitemgr/sitemgr-site/?category_id=4[XSS]
For the SQL injection issues:
http://egroupware/tts/index.php?filter=u99[SQL]
http://egroupware/tts/index.php?filter=c99[SQL]
http://egroupware/index.php?menuaction=preferences.uicategories.index&cats_app=foobar[SQL]
An exploit is not required. The following proof of concepts were supplied:
For the cross-site scripting issues:
http://egroupware/index.php?menuaction=addressbook.uiaddressbook.edit&ab_id=11[XSS]
http://egroupware/index.php?menuaction=manual.uimanual.view&page=ManualAddressbook[XSS]
http://egroupware/index.php?menuaction=forum.uiforum.post&type=new[XSS]
http://egroupware/wiki/index.php?page=RecentChanges[XSS]
http://egroupware/wiki/index.php?action=history&page=WikkiTikkiTavi&lang=en[XSS]
http://egroupware/index.php?menuaction=wiki.uiwiki.edit&page=setup[XSS]
http://egroupware/sitemgr/sitemgr-site/?category_id=4[XSS]
For the SQL injection issues:
http://egroupware/tts/index.php?filter=u99[SQL]
http://egroupware/tts/index.php?filter=c99[SQL]
http://egroupware/index.php?menuaction=preferences.uicategories.index&cats_app=foobar[SQL]
Solution / Fix
eGroupWare Multiple Cross-Site Scripting and SQL Injection Vulnerabilities
Solution:
Gentoo has released advisory GLSA 200504-24 and a fix to address this issue. To obtain the upgrade, enter the following commands:
emerge --sync
emerge --ask --oneshot --verbose ">=www-apps/egroupware-1.0.0.007"
A fix is available:
eGroupWare eGroupWare 1.0
eGroupWare eGroupWare 1.0.1
eGroupWare eGroupWare 1.0.3
eGroupWare eGroupWare 1.0.6
Solution:
Gentoo has released advisory GLSA 200504-24 and a fix to address this issue. To obtain the upgrade, enter the following commands:
emerge --sync
emerge --ask --oneshot --verbose ">=www-apps/egroupware-1.0.0.007"
A fix is available:
eGroupWare eGroupWare 1.0
-
eGroupWare eGroupWare 1.0.0.007
http://sourceforge.net/project/showfiles.php?group_id=78745
eGroupWare eGroupWare 1.0.1
-
eGroupWare eGroupWare 1.0.0.007
http://sourceforge.net/project/showfiles.php?group_id=78745
eGroupWare eGroupWare 1.0.3
-
eGroupWare eGroupWare 1.0.0.007
http://sourceforge.net/project/showfiles.php?group_id=78745
eGroupWare eGroupWare 1.0.6
-
eGroupWare eGroupWare 1.0.0.007
http://sourceforge.net/project/showfiles.php?group_id=78745
References
eGroupWare Multiple Cross-Site Scripting and SQL Injection Vulnerabilities
References:
References:
- eGroupWare Homepage (eGroupWare)
- Release Notes: eGroupWare 1.0.0.007 (eGroupWare)
- Multiple eGroupware Vulnerabilities ("GulfTech Security Research"
)