Horde IMP and Groupware Webmail Edition Multiple Input Validation Vulnerabilities
BID:27223
Info
Horde IMP and Groupware Webmail Edition Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 27223 |
| Class: | Access Validation Error |
| CVE: |
CVE-2007-6018 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 10 2008 12:00AM |
| Updated: | Apr 13 2015 09:12PM |
| Credit: | Ulf Harnhammar of Secunia Research discovered these issues. |
| Vulnerable: |
Redhat Fedora 7 Horde Project IMP 4.1.5 Horde Project Horde 3.1.5 Horde Project Horde 3.1.3 Horde Project Groupware Webmail Edition 1.0.3 Horde Framework 3.1.5 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
Horde Project Horde 3.1.6 Horde Project Groupware Webmail Edition 1.0.4 |
Discussion
Horde IMP and Groupware Webmail Edition Multiple Input Validation Vulnerabilities
Horde IMP and Groupware Webmail Edition are prone to multiple input-validation vulnerabilities because the software fails to sanitize certain HTML and HTTP data.
Attackers can leverage these issues to have malicious HTML rendered in the client, to delete arbitrary email messages, and to purge deleted email messages.
IMP 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3 are vulnerable; other versions may also be affected.
Horde IMP and Groupware Webmail Edition are prone to multiple input-validation vulnerabilities because the software fails to sanitize certain HTML and HTTP data.
Attackers can leverage these issues to have malicious HTML rendered in the client, to delete arbitrary email messages, and to purge deleted email messages.
IMP 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3 are vulnerable; other versions may also be affected.
Exploit / POC
Horde IMP and Groupware Webmail Edition Multiple Input Validation Vulnerabilities
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Horde IMP and Groupware Webmail Edition Multiple Input Validation Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Horde Project Groupware Webmail Edition 1.0.3
Horde Project Horde 3.1.5
Solution:
Updates are available. Please see the references for more information.
Horde Project Groupware Webmail Edition 1.0.3
-
Horde horde-webmail-1.0.4.tar.gz
http://ftp.horde.org/pub/horde-webmail/horde-webmail-1.0.4.tar.gz
Horde Project Horde 3.1.5
-
Horde horde-3.1.6.tar.gz
ftp://ftp.horde.org/pub/horde/horde-3.1.6.tar.gz
References
Horde IMP and Groupware Webmail Edition Multiple Input Validation Vulnerabilities
References:
References:
- [announce] Horde Groupware 1.0.3 (final) (Horde)
- [announce] Horde Groupware Webmail Edition 1.0.4 (final) (Horde)
- Pandora Homepage (Pandora FMS Team)
- Secunia Research: IMP Mail Deletion Security Bypass Vulnerability (Secunia Research)