Horde Kronolith Multiple HTML Injection Vulnerabilities
BID:15808
Info
Horde Kronolith Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 15808 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-4189 CVE-2005-4190 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 12 2005 12:00AM |
| Updated: | Mar 19 2015 08:21AM |
| Credit: | Johannes Greil of SEC Consult is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 7 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise Desktop 10 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. SuSE Linux Open-Xchange 4.1 S.u.S.E. SUSE CORE 9 for x86 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Open-Enterprise-Server 1 S.u.S.E. Office Server S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Professional 7.3 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Openexchange Server S.u.S.E. Linux Office Server S.u.S.E. Linux Enterprise Server for S/390 9.0 S.u.S.E. Linux Enterprise Server for S/390 S.u.S.E. Linux Desktop 1.0 S.u.S.E. Linux Database Server 0 S.u.S.E. Linux Connectivity Server Horde Project Kronolith 2.0.5 Horde Project Kronolith 2.0.4 Horde Project Kronolith 1.1.4 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: |
Horde Project Kronolith 2.0.6 |
Discussion
Horde Kronolith Multiple HTML Injection Vulnerabilities
Kronolith is prone to multiple HTML-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit these issues to control how the site is rendered to the user; other attacks are also possible.
Kronolith is prone to multiple HTML-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit these issues to control how the site is rendered to the user; other attacks are also possible.
Exploit / POC
Horde Kronolith Multiple HTML Injection Vulnerabilities
No exploit is required.
No exploit is required.
Solution / Fix
Horde Kronolith Multiple HTML Injection Vulnerabilities
Solution:
Fixes are available.
Please see the referenced vendor advisories for details on obtaining and applying the appropriate updates.
Horde Project Kronolith 1.1.4
Horde Project Kronolith 2.0.4
Horde Project Kronolith 2.0.5
Solution:
Fixes are available.
Please see the referenced vendor advisories for details on obtaining and applying the appropriate updates.
Horde Project Kronolith 1.1.4
-
Debian kronolith_1.1.4-2sarge1_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/k/kronolith/kronolith_1.1 .4-2sarge1_all.deb
Horde Project Kronolith 2.0.4
-
Horde kronolith-h3-2.0.6.tar.gz
ftp://ftp.horde.org/pub/kronolith/kronolith-h3-2.0.6.tar.gz
Horde Project Kronolith 2.0.5
-
Horde kronolith-h3-2.0.6.tar.gz
ftp://ftp.horde.org/pub/kronolith/kronolith-h3-2.0.6.tar.gz
References
Horde Kronolith Multiple HTML Injection Vulnerabilities
References:
References:
- kronolith -- missing input sanitising (Debian)
- Kronolith Homepage (Horde Project)
- Pandora Homepage (Pandora FMS Team)
- SEC Consult Security Advisory < 20051211-0 > (SEC-CONSULT)