eGroupWare CLASS.UICATEGORIES.INC.PHP Multiple Cross-Site Scripting Vulnerabilities
BID:25800
Info
eGroupWare CLASS.UICATEGORIES.INC.PHP Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 25800 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-5091 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 16 2007 12:00AM |
| Updated: | May 07 2015 05:35PM |
| Credit: | Enrico Milanese is credited with the discovery of this vulnerability. |
| Vulnerable: |
eGroupWare eGroupWare 1.4.1 |
| Not Vulnerable: | |
Discussion
eGroupWare CLASS.UICATEGORIES.INC.PHP Multiple Cross-Site Scripting Vulnerabilities
eGroupWare is prone to multiple cross-site scripting vulnerabilities.
These issues affect the 'class.uicategories.inc.php' script.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
These issues affect eGroupWare 1.4.001; other versions may also be affected.
eGroupWare is prone to multiple cross-site scripting vulnerabilities.
These issues affect the 'class.uicategories.inc.php' script.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
These issues affect eGroupWare 1.4.001; other versions may also be affected.
Exploit / POC
eGroupWare CLASS.UICATEGORIES.INC.PHP Multiple Cross-Site Scripting Vulnerabilities
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
eGroupWare CLASS.UICATEGORIES.INC.PHP Multiple Cross-Site Scripting Vulnerabilities
Solution:
Vendor fixes are available in the SVN repository.
Solution:
Vendor fixes are available in the SVN repository.
References
eGroupWare CLASS.UICATEGORIES.INC.PHP Multiple Cross-Site Scripting Vulnerabilities
References:
References:
- eGroupWare Homepage (eGroupWare)
- Revision 24443 (eGroupWare)