SquirrelMail Address Add Plugin Add.PHP Cross-Site Scripting Vulnerability
BID:14973
Info
SquirrelMail Address Add Plugin Add.PHP Cross-Site Scripting Vulnerability
| Bugtraq ID: | 14973 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-3128 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 29 2005 12:00AM |
| Updated: | Aug 02 2007 12:05AM |
| Credit: | The vendor has released this vulnerability. |
| Vulnerable: |
SquirrelMail SquirrelMail 1.4.2 Moritz Naumann SquirrelMail Address Add Plugin 2.0 Moritz Naumann SquirrelMail Address Add Plugin 1.9 Apple Mac OS X Server 10.4.10 Apple Mac OS X Server 10.4.9 Apple Mac OS X Server 10.4.8 Apple Mac OS X Server 10.4.7 Apple Mac OS X Server 10.4.6 Apple Mac OS X Server 10.4.5 Apple Mac OS X Server 10.4.4 Apple Mac OS X Server 10.4.3 Apple Mac OS X Server 10.4.2 Apple Mac OS X Server 10.4.1 Apple Mac OS X Server 10.4 Apple Mac OS X Server 10.3.9 Apple Mac OS X 10.4.10 Apple Mac OS X 10.4.9 Apple Mac OS X 10.4.8 Apple Mac OS X 10.4.7 Apple Mac OS X 10.4.6 Apple Mac OS X 10.4.5 Apple Mac OS X 10.4.4 Apple Mac OS X 10.4.3 Apple Mac OS X 10.4.2 Apple Mac OS X 10.4.1 Apple Mac OS X 10.4 Apple Mac OS X 10.3.9 |
| Not Vulnerable: |
Moritz Naumann SquirrelMail Address Add Plugin 2.1 |
Discussion
SquirrelMail Address Add Plugin Add.PHP Cross-Site Scripting Vulnerability
SquirrelMail Address Add Plugin is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
SquirrelMail Address Add Plugin is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
SquirrelMail Address Add Plugin Add.PHP Cross-Site Scripting Vulnerability
No exploit is required.
An example URI has been provided:
http://www.example.com/squirrelmail_root_dir/plugins/address_add/add.php?first=HOVER%20ME!%22%20onMouseOver=%22alert('foo');
No exploit is required.
An example URI has been provided:
http://www.example.com/squirrelmail_root_dir/plugins/address_add/add.php?first=HOVER%20ME!%22%20onMouseOver=%22alert('foo');
Solution / Fix
SquirrelMail Address Add Plugin Add.PHP Cross-Site Scripting Vulnerability
Solution:
Mandriva Linux has released security advisory MDKSA-2005:178 addressing this issue. Please see the referenced advisory for details.
The vendor has released version 2.1 to address this issue.
SquirrelMail SquirrelMail 1.4.2
Moritz Naumann SquirrelMail Address Add Plugin 1.9
Apple Mac OS X 10.3.9
Apple Mac OS X Server 10.3.9
Apple Mac OS X 10.4.10
Apple Mac OS X Server 10.4.10
Moritz Naumann SquirrelMail Address Add Plugin 2.0
Solution:
Mandriva Linux has released security advisory MDKSA-2005:178 addressing this issue. Please see the referenced advisory for details.
The vendor has released version 2.1 to address this issue.
SquirrelMail SquirrelMail 1.4.2
-
Mandriva squirrelmail-1.4.2-11.2.C30mdk.noarch.rpm
Corporate 3.0/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva squirrelmail-1.4.2-11.2.C30mdk.noarch.rpm
Corporate 3.0:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva squirrelmail-poutils-1.4.2-11.2.C30mdk.noarch.rpm
Corporate 3.0:
http://www1.mandrivalinux.com/en/ftp.php3
Moritz Naumann SquirrelMail Address Add Plugin 1.9
-
SquirrelMail address_add-2.1-1.4.0.tar.gz
http://www.squirrelmail.org/plugins/address_add-2.1-1.4.0.tar.gz
Apple Mac OS X 10.3.9
-
Apple SecUpd2007-007Pan.dmg For Mac OS X v10.3.9
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.3.9
-
Apple SecUpdSrvr2007-007Pan.dmg For Mac OS X Server v10.3.9
http://www.apple.com/support/downloads/
Apple Mac OS X 10.4.10
-
Apple SecUpd2007-007Ti.dmg For Mac OS X v10.4.10 (PowerPC)
http://www.apple.com/support/downloads/ -
Apple SecUpd2007-007Univ.dmg For Mac OS X v10.4.10 (Universal)
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.4.10
-
Apple SecUpdSrvr2007-007Ti.dmg For Mac OS X Server v10.4.10 (PowerPC)
http://www.apple.com/support/downloads/ -
Apple SecUpdSrvr2007-007Universal.dmg For Mac OS X Server v10.4.10 (Universal)
http://www.apple.com/support/downloads/
Moritz Naumann SquirrelMail Address Add Plugin 2.0
-
SquirrelMail address_add-2.1-1.4.0.tar.gz
http://www.squirrelmail.org/plugins/address_add-2.1-1.4.0.tar.gz
References
SquirrelMail Address Add Plugin Add.PHP Cross-Site Scripting Vulnerability
References:
References:
- Moritz Naumann SquirrelMail Address Add Plugin Web Page (Moritz Naumann IT Consulting & Services)
- Vendor Homepage (SquirrelMail)
- SquirrelMail Address Add Plugin XSS ([email protected])