Horde Turba Multiple HTML Injection Vulnerabilities
BID:15802
Info
Horde Turba Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 15802 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-4190 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 12 2005 12:00AM |
| Updated: | Jul 19 2006 06:57PM |
| Credit: | Johannes Greil is credited with the discovery of this vulnerability. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SuSE Suse Linux Enterprise Desktop 10 SuSE Linux Openexchange Server SuSE Linux Enterprise Server 9 SuSE Linux Desktop 1.0 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. SuSE Linux Open-Xchange 4.1 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Open-Enterprise-Server 1 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Office Server S.u.S.E. Linux Enterprise Server for S/390 9.0 S.u.S.E. Linux Enterprise Server for S/390 S.u.S.E. Linux Database Server 0 S.u.S.E. Linux Connectivity Server Horde Turba Contact Manager 2.0.4 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: |
Horde Turba Contact Manager 2.0.5 |
Discussion
Horde Turba Multiple HTML Injection Vulnerabilities
Turba is prone to multiple HTML-injection vulnerabilities because the application fails to properly validate user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing attackers to steal cookie-based authentication credentials. An attacker could also exploit these issues to control how the site is rendered to the user; other attacks are also possible.
Turba is prone to multiple HTML-injection vulnerabilities because the application fails to properly validate user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing attackers to steal cookie-based authentication credentials. An attacker could also exploit these issues to control how the site is rendered to the user; other attacks are also possible.
Exploit / POC
Horde Turba Multiple HTML Injection Vulnerabilities
No exploit is required.
No exploit is required.
Solution / Fix
Horde Turba Multiple HTML Injection Vulnerabilities
Solution:
The vendor has released version 2.0.5 to address this issue.
Please see the references for more information and vendor advisories.
Horde Turba Contact Manager 2.0.4
Solution:
The vendor has released version 2.0.5 to address this issue.
Please see the references for more information and vendor advisories.
Horde Turba Contact Manager 2.0.4
-
Horde turba-h3-2.0.5.tar.gz
http://ftp.horde.org/pub/turba/turba-h3-2.0.5.tar.gz
References
Horde Turba Multiple HTML Injection Vulnerabilities
References:
References:
- Horde Advisory for Turba Vulnerabilities (Horde)
- Turba Contact Manager (Horde Project)