Horde Application Framework Multiple Cross-Site Scripting Vulnerabilities
BID:18436
Info
Horde Application Framework Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 18436 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-2195 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 14 2006 12:00AM |
| Updated: | Jul 17 2006 05:13PM |
| Credit: | Michael Marek is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 10 SuSE Suse Linux Enterprise Desktop 10 SuSE Linux Openexchange Server SuSE Linux Enterprise Server 9 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 10.1 Horde Project Horde 3.0.4 -RC 2 Horde Project Horde 3.0.4 -RC 1 Horde Project Horde 3.0.4 Horde Project Horde 2.2.8 Gentoo www-apps/horde 3.1.1 r1 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: | |
Discussion
Horde Application Framework Multiple Cross-Site Scripting Vulnerabilities
Horde is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Horde is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
Horde Application Framework Multiple Cross-Site Scripting Vulnerabilities
Attackers exploit these issues by enticing a victim to follow a malicious link that includes hostile HTML and script code.
Attackers exploit these issues by enticing a victim to follow a malicious link that includes hostile HTML and script code.
Solution / Fix
Horde Application Framework Multiple Cross-Site Scripting Vulnerabilities
Solution:
The vendor has released patches to address these issues; please see the advisory section for details.
mailto:[email protected]
Horde Project Horde 2.2.8
Horde Project Horde 3.0.4
Solution:
The vendor has released patches to address these issues; please see the advisory section for details.
mailto:[email protected]
Horde Project Horde 2.2.8
-
Debian horde2_2.2.8-1sarge3_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/horde2/horde2_2.2.8-1sa rge3_all.deb
Horde Project Horde 3.0.4
-
Debian horde3_3.0.4-4sarge4_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/horde3/horde3_3.0.4-4sa rge4_all.deb
References
Horde Application Framework Multiple Cross-Site Scripting Vulnerabilities
References:
References:
- Pandora Homepage (Pandora FMS Team)
- [SECURITY] [DSA 1098-1] New horde3 packages fix cross-site scripting (Moritz Muehlenhoff
) - [SECURITY] [DSA 1099-1] New horde2 packages fix cross-site scripting (Moritz Muehlenhoff
)