RETIRED: eGroupWare '_bad_protocol_once()' HTML Security Bypass Vulnerability
BID:28424
Info
RETIRED: eGroupWare '_bad_protocol_once()' HTML Security Bypass Vulnerability
| Bugtraq ID: | 28424 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 24 2008 12:00AM |
| Updated: | Apr 03 2008 09:29PM |
| Credit: | lukasz.pilorz |
| Vulnerable: |
eGroupWare eGroupWare 1.4.2 eGroupWare eGroupWare 1.4.1 eGroupWare eGroupWare 1.0.6 eGroupWare eGroupWare 1.0.3 eGroupWare eGroupWare 1.0.1 eGroupWare eGroupWare 1.0 .0.009 eGroupWare eGroupWare 1.0 .0.007 eGroupWare eGroupWare 1.0 eGroupWare eGroupWare 1.2.107-2 eGroupWare eGroupWare 1.2.106-2 |
| Not Vulnerable: |
eGroupWare eGroupWare 1.4.3 |
Discussion
RETIRED: eGroupWare '_bad_protocol_once()' HTML Security Bypass Vulnerability
eGroupWare is prone to a vulnerability that allows arbitrary code to bypass HTML filtering.
An attacker can exploit this issue to execute arbitrary script code in the context of the application, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
Versions prior to eGroupWare 1.4.003 are vulnerable; other versions may also be affected.
NOTE: This BID is now retired. It has been incorporated into BID 28599 (kses Multiple Input Validation Vulnerabilities), because the underlying problems are caused by the kses HTML filter.
eGroupWare is prone to a vulnerability that allows arbitrary code to bypass HTML filtering.
An attacker can exploit this issue to execute arbitrary script code in the context of the application, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
Versions prior to eGroupWare 1.4.003 are vulnerable; other versions may also be affected.
NOTE: This BID is now retired. It has been incorporated into BID 28599 (kses Multiple Input Validation Vulnerabilities), because the underlying problems are caused by the kses HTML filter.
Exploit / POC
RETIRED: eGroupWare '_bad_protocol_once()' HTML Security Bypass Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
RETIRED: eGroupWare '_bad_protocol_once()' HTML Security Bypass Vulnerability
Solution:
The vendor released eGroupWare 1.4.003 to address this issue. Please see the references for more information.
eGroupWare eGroupWare 1.2.107-2
eGroupWare eGroupWare 1.2.106-2
eGroupWare eGroupWare 1.0 .0.009
eGroupWare eGroupWare 1.0
eGroupWare eGroupWare 1.0 .0.007
eGroupWare eGroupWare 1.0.1
eGroupWare eGroupWare 1.0.3
eGroupWare eGroupWare 1.0.6
eGroupWare eGroupWare 1.4.1
eGroupWare eGroupWare 1.4.2
Solution:
The vendor released eGroupWare 1.4.003 to address this issue. Please see the references for more information.
eGroupWare eGroupWare 1.2.107-2
-
eGroupWare eGroupWare-1.4.003-2.tar.gz
http://downloads.sourceforge.net/egroupware/eGroupWare-1.4.003-2.tar.g z?modtime=1205969346&big_mirror=1
eGroupWare eGroupWare 1.2.106-2
-
eGroupWare eGroupWare-1.4.003-2.tar.gz
http://downloads.sourceforge.net/egroupware/eGroupWare-1.4.003-2.tar.g z?modtime=1205969346&big_mirror=1
eGroupWare eGroupWare 1.0 .0.009
-
eGroupWare eGroupWare-1.4.003-2.tar.gz
http://downloads.sourceforge.net/egroupware/eGroupWare-1.4.003-2.tar.g z?modtime=1205969346&big_mirror=1
eGroupWare eGroupWare 1.0
-
eGroupWare eGroupWare-1.4.003-2.tar.gz
http://downloads.sourceforge.net/egroupware/eGroupWare-1.4.003-2.tar.g z?modtime=1205969346&big_mirror=1
eGroupWare eGroupWare 1.0 .0.007
-
eGroupWare eGroupWare-1.4.003-2.tar.gz
http://downloads.sourceforge.net/egroupware/eGroupWare-1.4.003-2.tar.g z?modtime=1205969346&big_mirror=1
eGroupWare eGroupWare 1.0.1
-
eGroupWare eGroupWare-1.4.003-2.tar.gz
http://downloads.sourceforge.net/egroupware/eGroupWare-1.4.003-2.tar.g z?modtime=1205969346&big_mirror=1
eGroupWare eGroupWare 1.0.3
-
eGroupWare eGroupWare-1.4.003-2.tar.gz
http://downloads.sourceforge.net/egroupware/eGroupWare-1.4.003-2.tar.g z?modtime=1205969346&big_mirror=1
eGroupWare eGroupWare 1.0.6
-
eGroupWare eGroupWare-1.4.003-2.tar.gz
http://downloads.sourceforge.net/egroupware/eGroupWare-1.4.003-2.tar.g z?modtime=1205969346&big_mirror=1
eGroupWare eGroupWare 1.4.1
-
eGroupWare eGroupWare-1.4.003-2.tar.gz
http://downloads.sourceforge.net/egroupware/eGroupWare-1.4.003-2.tar.g z?modtime=1205969346&big_mirror=1
eGroupWare eGroupWare 1.4.2
-
eGroupWare eGroupWare-1.4.003-2.tar.gz
http://downloads.sourceforge.net/egroupware/eGroupWare-1.4.003-2.tar.g z?modtime=1205969346&big_mirror=1
References
RETIRED: eGroupWare '_bad_protocol_once()' HTML Security Bypass Vulnerability
References:
References:
- eGroupWare 1.4.003 Changelog (eGroupWare)
- eGroupWare Homepage (eGroupWare)