Groove Networks Groove Virtual Office SharePoint Lists Arbitrary Script Injection Vulnerability
BID:13684
Info
Groove Networks Groove Virtual Office SharePoint Lists Arbitrary Script Injection Vulnerability
| Bugtraq ID: | 13684 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 19 2005 12:00AM |
| Updated: | May 19 2005 12:00AM |
| Credit: | This issue was reported by US-CERT. |
| Vulnerable: |
Groove Networks Workspace 2.5 Groove Networks Workspace 2.0 Groove Networks Virtual Office 3.1 a Groove Networks Virtual Office 3.1 Groove Networks Virtual Office 3.0 |
| Not Vulnerable: |
Groove Networks Workspace 2.5 n build 1871 Groove Networks Virtual Office 3.1 build 2338 Groove Networks Virtual Office 3.1 a build 2364 |
Discussion
Groove Networks Groove Virtual Office SharePoint Lists Arbitrary Script Injection Vulnerability
Groove Virtual Office is affected by an arbitrary script injection vulnerability.
User-supplied data is not properly sanitized from SharePoint lists and is copied into Groove Mobile Workspace. This can allow an attacker to inject and execute script code in the context of the application, which can lead to various attacks.
Groove Virtual Office is affected by an arbitrary script injection vulnerability.
User-supplied data is not properly sanitized from SharePoint lists and is copied into Groove Mobile Workspace. This can allow an attacker to inject and execute script code in the context of the application, which can lead to various attacks.
Exploit / POC
Groove Networks Groove Virtual Office SharePoint Lists Arbitrary Script Injection Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Groove Networks Groove Virtual Office SharePoint Lists Arbitrary Script Injection Vulnerability
Solution:
The vendor has released updates to address this issue. Updates are available from the following locations:
3.x releases:
http://www.groove.net/update
2.x releases:
http://www.groove.net/archive
Solution:
The vendor has released updates to address this issue. Updates are available from the following locations:
3.x releases:
http://www.groove.net/update
2.x releases:
http://www.groove.net/archive
References
Groove Networks Groove Virtual Office SharePoint Lists Arbitrary Script Injection Vulnerability
References:
References:
- Home Page (Groove Networks)
- Vulnerability Note VU#514386 - Groove Mobile Workspace vulnerable to script (CERT)