kses Multiple Input Validation Vulnerabilities
BID:28599
Info
kses Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 28599 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1502 CVE-2008-1222 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 03 2008 12:00AM |
| Updated: | May 07 2015 06:19PM |
| Credit: | Lukasz Pilorz |
| Vulnerable: |
WordPress Wordpress (B2) 0.6.2 .1 WordPress Wordpress (B2) 0.6.2 WordPress WordPress 2.3.3 WordPress WordPress 2.3.2 WordPress WordPress 2.3.1 WordPress WordPress 2.2.3 WordPress WordPress 2.2.2 WordPress WordPress 2.2.1 WordPress WordPress 2.1.3 WordPress WordPress 2.1.2 WordPress WordPress 2.1.1 WordPress WordPress 2.0.11 WordPress WordPress 2.0.10 WordPress WordPress 2.0.7 WordPress WordPress 2.0.6 WordPress WordPress 2.0.5 WordPress WordPress 2.0.4 WordPress WordPress 2.0.3 WordPress WordPress 2.0.2 WordPress WordPress 2.0.1 WordPress WordPress 2.0 WordPress WordPress 1.5.2 WordPress WordPress 1.5.1 .3 WordPress WordPress 1.5.1 .2 WordPress WordPress 1.5.1 WordPress WordPress 1.5 WordPress WordPress 1.3.1 WordPress WordPress 1.2.2 WordPress WordPress 1.2.1 WordPress WordPress 1.2 WordPress WordPress 0.71 WordPress WordPress 0.7 WordPress WordPress 2.3 WordPress WordPress 2.2 Revision 5003 WordPress WordPress 2.2 Revision 5002 WordPress WordPress 2.2 WordPress WordPress 2.1.3-RC2 WordPress WordPress 2.1.3-RC1 WordPress WordPress 2.1 WordPress WordPress 2.0.10-RC2 WordPress WordPress 2.0.10-RC1 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 lpia Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 SuSE openSUSE 10.3 S.u.S.E. openSUSE 10.2 Moodle moodle 1.8.4 Moodle moodle 1.8.3 Moodle moodle 1.7.1 Moodle moodle 1.6.2 Moodle moodle 1.6.1 Moodle moodle 1.6 dev Moodle moodle 1.5.2 Moodle moodle 1.5.1 Moodle moodle 1.5 Moodle moodle 1.4.3 Moodle moodle 1.4.2 Moodle moodle 1.4.1 Moodle moodle 1.3.4 Moodle moodle 1.3.3 Moodle moodle 1.3.2 Moodle moodle 1.3.1 Moodle moodle 1.3 Moodle moodle 1.6.1 + MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 kses kses 0.2.2 Gentoo Linux eGroupWare eGroupWare 1.4.2 eGroupWare eGroupWare 1.4.1 eGroupWare eGroupWare 1.0.6 eGroupWare eGroupWare 1.0.3 eGroupWare eGroupWare 1.0.1 eGroupWare eGroupWare 1.0 .0.009 eGroupWare eGroupWare 1.0 .0.007 eGroupWare eGroupWare 1.0 eGroupWare eGroupWare 1.2.107-2 eGroupWare eGroupWare 1.2.106-2 Dokeos Open Source Learning & Knowledge Management Tool 1.8.4 SP2 Dokeos Open Source Learning & Knowledge Management Tool 1.8.4 Dokeos Open Source Learning & Knowledge Management Tool 1.8 Dokeos Open Source Learning & Knowledge Management Tool 1.6.5 Dokeos Open Source Learning & Knowledge Management Tool 1.6.4 Dokeos Open Source Learning & Knowledge Management Tool 1.6 RC2 Dokeos Open Source Learning & Knowledge Management Tool 1.5.5 Dokeos Open Source Learning & Knowledge Management Tool 1.5.4 Dokeos Open Source Learning & Knowledge Management Tool 1.5.3 Dokeos Open Source Learning & Knowledge Management Tool 1.5 Dokeos Open Source Learning & Knowledge Management Tool 1.4 Dokeos Open Source Learning & Knowledge Management Tool 1.8.4 SP1 Dokeos Open Source Learning & Knowledge Management Tool 1.6.4 (P1) Dokeos Open Source Learning & Knowledge Management 1.8.4 Dokeos Open Source Learning & Knowledge Management 1.8 Dokeos Open Source Learning & Knowledge Management 1.8.4 SP3 Dokeos Open Source Learning & Knowledge Management 1.8.4 SP1 Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 armel Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 BEA Systems Weblogic Proxy Plugin 1.5.3 + BEA Systems Weblogic Proxy Plugin 1.5.3 |
| Not Vulnerable: |
WordPress WordPress 2.5 Moodle moodle 1.8.5 Moodle moodle 1.9 eGroupWare eGroupWare 1.4.3 Dokeos Open Source Learning & Knowledge Management Tool 1.8.4 SP3 |
Discussion
kses Multiple Input Validation Vulnerabilities
The kses HTML filter is prone to multiple input-validation vulnerabilities that can lead to client-side script execution.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks. PHP code execution is also reportedly possible, but may be exploitable only in limited -- and unknown -- circumstances.
The issues are known to affect the following multiple projects that have incorporated kses:
Dokeos prior to 1.8.4 SP3
eGroupWare prior to 1.4.003
WordPress prior to 2.5
Moodle prior to 1.9
Other applications may also be affected.
NOTE: These issues were previously documented in the following BIDs:
28424 eGroupWare '_bad_protocol_once()' HTML Security Bypass Vulnerability
28121 Dokeos Multiple Remote Code Execution and Cross-Site Scripting Vulnerabilities
Since these issues were determined to originate in the same kses-based source code, this BID has been created to cover all the affected packages.
The kses HTML filter is prone to multiple input-validation vulnerabilities that can lead to client-side script execution.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks. PHP code execution is also reportedly possible, but may be exploitable only in limited -- and unknown -- circumstances.
The issues are known to affect the following multiple projects that have incorporated kses:
Dokeos prior to 1.8.4 SP3
eGroupWare prior to 1.4.003
WordPress prior to 2.5
Moodle prior to 1.9
Other applications may also be affected.
NOTE: These issues were previously documented in the following BIDs:
28424 eGroupWare '_bad_protocol_once()' HTML Security Bypass Vulnerability
28121 Dokeos Multiple Remote Code Execution and Cross-Site Scripting Vulnerabilities
Since these issues were determined to originate in the same kses-based source code, this BID has been created to cover all the affected packages.
Exploit / POC
kses Multiple Input Validation Vulnerabilities
Attackers can exploit the cross-site scripting issues by enticing an unsuspecting user to follow a malicious URI. Attackers can exploit the code-execution vulnerability with a browser.
The following proof-of-concept URIs and exploit code are available:
Attackers can exploit the cross-site scripting issues by enticing an unsuspecting user to follow a malicious URI. Attackers can exploit the code-execution vulnerability with a browser.
The following proof-of-concept URIs and exploit code are available:
Solution / Fix
kses Multiple Input Validation Vulnerabilities
Solution:
Reportedly, the kses project has been abandoned.
Fixes and advisories are available for several projects that incorporate vulnerable versions of kses. Please see the references for more information.
Ubuntu Ubuntu Linux 7.10 powerpc
WordPress WordPress 2.1
Debian Linux 5.0 alpha
eGroupWare eGroupWare 1.2.106-2
Debian Linux 4.0 amd64
Debian Linux 4.0 ia-32
WordPress WordPress 2.0.10-RC2
Debian Linux 5.0 armel
Debian Linux 5.0 mips
Debian Linux 4.0 mips
Debian Linux 5.0 sparc
Debian Linux 4.0 arm
Debian Linux 4.0 powerpc
Debian Linux 4.0 m68k
Debian Linux 5.0 s/390
Ubuntu Ubuntu Linux 8.04 LTS lpia
Ubuntu Ubuntu Linux 7.10 lpia
WordPress WordPress 2.1.3-RC1
Debian Linux 5.0 hppa
Debian Linux 4.0 sparc
Debian Linux 5.0 m68k
WordPress WordPress 2.2 Revision 5003
Ubuntu Ubuntu Linux 7.10 amd64
Ubuntu Ubuntu Linux 8.04 LTS i386
eGroupWare eGroupWare 1.2.107-2
Debian Linux 5.0 ia-64
Ubuntu Ubuntu Linux 8.04 LTS powerpc
Ubuntu Ubuntu Linux 8.04 LTS sparc
Moodle moodle 1.6.1 +
WordPress WordPress 0.7
eGroupWare eGroupWare 1.0 .0.007
eGroupWare eGroupWare 1.0.1
eGroupWare eGroupWare 1.0.3
eGroupWare eGroupWare 1.0.6
WordPress WordPress 1.2
WordPress WordPress 1.2.1
WordPress WordPress 1.2.2
Moodle moodle 1.3
WordPress WordPress 1.3.1
Moodle moodle 1.3.2
Moodle moodle 1.3.3
Moodle moodle 1.3.4
Moodle moodle 1.4.1
eGroupWare eGroupWare 1.4.1
eGroupWare eGroupWare 1.4.2
Moodle moodle 1.4.2
Moodle moodle 1.4.3
Moodle moodle 1.5
Moodle moodle 1.5.1
WordPress WordPress 1.5.1
WordPress WordPress 1.5.1 .2
WordPress WordPress 1.5.2
Moodle moodle 1.5.2
BEA Systems Weblogic Proxy Plugin 1.5.3 +
Moodle moodle 1.6 dev
Moodle moodle 1.6.1
Moodle moodle 1.6.2
Moodle moodle 1.7.1
Moodle moodle 1.8.3
Dokeos Open Source Learning & Knowledge Management Tool 1.8.4 SP2
WordPress WordPress 2.0
WordPress WordPress 2.0.1
WordPress WordPress 2.0.11
WordPress WordPress 2.0.3
WordPress WordPress 2.0.5
WordPress WordPress 2.1.1
WordPress WordPress 2.1.2
WordPress WordPress 2.1.3
WordPress WordPress 2.2.1
WordPress WordPress 2.3.1
MandrakeSoft Corporate Server 3.0
Solution:
Reportedly, the kses project has been abandoned.
Fixes and advisories are available for several projects that incorporate vulnerable versions of kses. Please see the references for more information.
Ubuntu Ubuntu Linux 7.10 powerpc
-
Ubuntu moodle_1.8.2-1ubuntu2.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1ubu ntu2.1_all.deb
WordPress WordPress 2.1
-
WordPress Wordpress 2.5
http://wordpress.org/latest.tar.gz
Debian Linux 5.0 alpha
-
Debian wordpress_2.5.1-11+lenny1_all.deb
http://security.debian.org/pool/updates/main/w/wordpress/wordpress_2.5 .1-11+lenny1_all.deb
eGroupWare eGroupWare 1.2.106-2
-
eGroupWare eGroupWare-1.4.003-2.tar.gz
http://downloads.sourceforge.net/egroupware/eGroupWare-1.4.003-2.tar.g z?modtime=1205969346&big_mirror=1
Debian Linux 4.0 amd64
-
Debian moodle_1.6.3-2+etch1_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+e tch1_all.deb -
Debian wordpress_2.0.10-1etch4_all.deb
http://security.debian.org/pool/updates/main/w/wordpress/wordpress_2.0 .10-1etch4_all.deb
Debian Linux 4.0 ia-32
-
Debian moodle_1.6.3-2+etch1_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+e tch1_all.deb -
Debian wordpress_2.0.10-1etch4_all.deb
http://security.debian.org/pool/updates/main/w/wordpress/wordpress_2.0 .10-1etch4_all.deb
WordPress WordPress 2.0.10-RC2
-
WordPress Wordpress 2.5
http://wordpress.org/latest.tar.gz
Debian Linux 5.0 armel
-
Debian wordpress_2.5.1-11+lenny1_all.deb
http://security.debian.org/pool/updates/main/w/wordpress/wordpress_2.5 .1-11+lenny1_all.deb
Debian Linux 5.0 mips
-
Debian wordpress_2.5.1-11+lenny1_all.deb
http://security.debian.org/pool/updates/main/w/wordpress/wordpress_2.5 .1-11+lenny1_all.deb
Debian Linux 4.0 mips
-
Debian moodle_1.6.3-2+etch1_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+e tch1_all.deb -
Debian wordpress_2.0.10-1etch4_all.deb
http://security.debian.org/pool/updates/main/w/wordpress/wordpress_2.0 .10-1etch4_all.deb
Debian Linux 5.0 sparc
-
Debian wordpress_2.5.1-11+lenny1_all.deb
http://security.debian.org/pool/updates/main/w/wordpress/wordpress_2.5 .1-11+lenny1_all.deb
Debian Linux 4.0 arm
-
Debian moodle_1.6.3-2+etch1_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+e tch1_all.deb -
Debian wordpress_2.0.10-1etch4_all.deb
http://security.debian.org/pool/updates/main/w/wordpress/wordpress_2.0 .10-1etch4_all.deb
Debian Linux 4.0 powerpc
-
Debian moodle_1.6.3-2+etch1_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+e tch1_all.deb -
Debian wordpress_2.0.10-1etch4_all.deb
http://security.debian.org/pool/updates/main/w/wordpress/wordpress_2.0 .10-1etch4_all.deb
Debian Linux 4.0 m68k
-
Debian moodle_1.6.3-2+etch1_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+e tch1_all.deb -
Debian wordpress_2.0.10-1etch4_all.deb
http://security.debian.org/pool/updates/main/w/wordpress/wordpress_2.0 .10-1etch4_all.deb
Debian Linux 5.0 s/390
-
Debian wordpress_2.5.1-11+lenny1_all.deb
http://security.debian.org/pool/updates/main/w/wordpress/wordpress_2.5 .1-11+lenny1_all.deb
Ubuntu Ubuntu Linux 8.04 LTS lpia
-
Ubuntu moodle_1.8.2-1ubuntu4.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1ubu ntu4.1_all.deb
Ubuntu Ubuntu Linux 7.10 lpia
-
Ubuntu moodle_1.8.2-1ubuntu2.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1ubu ntu2.1_all.deb
WordPress WordPress 2.1.3-RC1
-
WordPress Wordpress 2.5
http://wordpress.org/latest.tar.gz
Debian Linux 5.0 hppa
-
Debian wordpress_2.5.1-11+lenny1_all.deb
http://security.debian.org/pool/updates/main/w/wordpress/wordpress_2.5 .1-11+lenny1_all.deb
Debian Linux 4.0 sparc
-
Debian moodle_1.6.3-2+etch1_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+e tch1_all.deb -
Debian wordpress_2.0.10-1etch4_all.deb
http://security.debian.org/pool/updates/main/w/wordpress/wordpress_2.0 .10-1etch4_all.deb
Debian Linux 5.0 m68k
-
Debian wordpress_2.5.1-11+lenny1_all.deb
http://security.debian.org/pool/updates/main/w/wordpress/wordpress_2.5 .1-11+lenny1_all.deb
WordPress WordPress 2.2 Revision 5003
-
WordPress Wordpress 2.5
http://wordpress.org/latest.tar.gz
Ubuntu Ubuntu Linux 7.10 amd64
-
Ubuntu moodle_1.8.2-1ubuntu2.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1ubu ntu2.1_all.deb
Ubuntu Ubuntu Linux 8.04 LTS i386
-
Ubuntu moodle_1.8.2-1ubuntu4.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1ubu ntu4.1_all.deb
eGroupWare eGroupWare 1.2.107-2
-
eGroupWare eGroupWare-1.4.003-2.tar.gz
http://downloads.sourceforge.net/egroupware/eGroupWare-1.4.003-2.tar.g z?modtime=1205969346&big_mirror=1
Debian Linux 5.0 ia-64
-
Debian wordpress_2.5.1-11+lenny1_all.deb
http://security.debian.org/pool/updates/main/w/wordpress/wordpress_2.5 .1-11+lenny1_all.deb
Ubuntu Ubuntu Linux 8.04 LTS powerpc
-
Ubuntu moodle_1.8.2-1ubuntu4.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1ubu ntu4.1_all.deb
Ubuntu Ubuntu Linux 8.04 LTS sparc
-
Ubuntu moodle_1.8.2-1ubuntu4.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1ubu ntu4.1_all.deb
Moodle moodle 1.6.1 +
-
Moodle moodle-1.9.tgz
http://download.moodle.org/download.php/stable19/moodle-1.9.tgz
WordPress WordPress 0.7
-
WordPress Wordpress 2.5
http://wordpress.org/latest.tar.gz
eGroupWare eGroupWare 1.0 .0.007
-
eGroupWare eGroupWare-1.4.003-2.tar.gz
http://downloads.sourceforge.net/egroupware/eGroupWare-1.4.003-2.tar.g z?modtime=1205969346&big_mirror=1
eGroupWare eGroupWare 1.0.1
-
eGroupWare eGroupWare-1.4.003-2.tar.gz
http://downloads.sourceforge.net/egroupware/eGroupWare-1.4.003-2.tar.g z?modtime=1205969346&big_mirror=1
eGroupWare eGroupWare 1.0.3
-
eGroupWare eGroupWare-1.4.003-2.tar.gz
http://downloads.sourceforge.net/egroupware/eGroupWare-1.4.003-2.tar.g z?modtime=1205969346&big_mirror=1
eGroupWare eGroupWare 1.0.6
-
eGroupWare eGroupWare-1.4.003-2.tar.gz
http://downloads.sourceforge.net/egroupware/eGroupWare-1.4.003-2.tar.g z?modtime=1205969346&big_mirror=1
WordPress WordPress 1.2
-
WordPress Wordpress 2.5
http://wordpress.org/latest.tar.gz
WordPress WordPress 1.2.1
-
WordPress Wordpress 2.5
http://wordpress.org/latest.tar.gz
WordPress WordPress 1.2.2
-
WordPress Wordpress 2.5
http://wordpress.org/latest.tar.gz
Moodle moodle 1.3
-
Moodle moodle-1.9.tgz
http://download.moodle.org/download.php/stable19/moodle-1.9.tgz
WordPress WordPress 1.3.1
-
WordPress Wordpress 2.5
http://wordpress.org/latest.tar.gz
Moodle moodle 1.3.2
-
Moodle moodle-1.9.tgz
http://download.moodle.org/download.php/stable19/moodle-1.9.tgz
Moodle moodle 1.3.3
-
Moodle moodle-1.9.tgz
http://download.moodle.org/download.php/stable19/moodle-1.9.tgz
Moodle moodle 1.3.4
-
Moodle moodle-1.9.tgz
http://download.moodle.org/download.php/stable19/moodle-1.9.tgz
Moodle moodle 1.4.1
-
Moodle moodle-1.9.tgz
http://download.moodle.org/download.php/stable19/moodle-1.9.tgz
eGroupWare eGroupWare 1.4.1
-
eGroupWare eGroupWare-1.4.003-2.tar.gz
http://downloads.sourceforge.net/egroupware/eGroupWare-1.4.003-2.tar.g z?modtime=1205969346&big_mirror=1
eGroupWare eGroupWare 1.4.2
-
eGroupWare eGroupWare-1.4.003-2.tar.gz
http://downloads.sourceforge.net/egroupware/eGroupWare-1.4.003-2.tar.g z?modtime=1205969346&big_mirror=1
Moodle moodle 1.4.2
-
Moodle moodle-1.9.tgz
http://download.moodle.org/download.php/stable19/moodle-1.9.tgz
Moodle moodle 1.4.3
-
Moodle moodle-1.9.tgz
http://download.moodle.org/download.php/stable19/moodle-1.9.tgz
Moodle moodle 1.5
-
Moodle moodle-1.9.tgz
http://download.moodle.org/download.php/stable19/moodle-1.9.tgz
Moodle moodle 1.5.1
-
Moodle moodle-1.9.tgz
http://download.moodle.org/download.php/stable19/moodle-1.9.tgz
WordPress WordPress 1.5.1
-
WordPress Wordpress 2.5
http://wordpress.org/latest.tar.gz
WordPress WordPress 1.5.1 .2
-
WordPress Wordpress 2.5
http://wordpress.org/latest.tar.gz
WordPress WordPress 1.5.2
-
WordPress Wordpress 2.5
http://wordpress.org/latest.tar.gz
Moodle moodle 1.5.2
-
Moodle moodle-1.9.tgz
http://download.moodle.org/download.php/stable19/moodle-1.9.tgz
BEA Systems Weblogic Proxy Plugin 1.5.3 +
-
Moodle moodle-1.9.tgz
http://download.moodle.org/download.php/stable19/moodle-1.9.tgz
Moodle moodle 1.6 dev
-
Moodle moodle-1.9.tgz
http://download.moodle.org/download.php/stable19/moodle-1.9.tgz
Moodle moodle 1.6.1
-
Moodle moodle-1.9.tgz
http://download.moodle.org/download.php/stable19/moodle-1.9.tgz
Moodle moodle 1.6.2
-
Moodle moodle-1.9.tgz
http://download.moodle.org/download.php/stable19/moodle-1.9.tgz
Moodle moodle 1.7.1
-
Moodle moodle-1.9.tgz
http://download.moodle.org/download.php/stable19/moodle-1.9.tgz
Moodle moodle 1.8.3
-
Moodle moodle-1.9.tgz
http://download.moodle.org/download.php/stable19/moodle-1.9.tgz
Dokeos Open Source Learning & Knowledge Management Tool 1.8.4 SP2
-
Dokeos dokeos-1.8.4-SP3.zip
http://www.dokeos.com/download/dokeos-1.8.4-SP3.zip
WordPress WordPress 2.0
-
WordPress Wordpress 2.5
http://wordpress.org/latest.tar.gz
WordPress WordPress 2.0.1
-
WordPress Wordpress 2.5
http://wordpress.org/latest.tar.gz
WordPress WordPress 2.0.11
-
WordPress Wordpress 2.5
http://wordpress.org/latest.tar.gz
WordPress WordPress 2.0.3
-
WordPress Wordpress 2.5
http://wordpress.org/latest.tar.gz
WordPress WordPress 2.0.5
-
WordPress Wordpress 2.5
http://wordpress.org/latest.tar.gz
WordPress WordPress 2.1.1
-
WordPress Wordpress 2.5
http://wordpress.org/latest.tar.gz
WordPress WordPress 2.1.2
-
WordPress Wordpress 2.5
http://wordpress.org/latest.tar.gz
WordPress WordPress 2.1.3
-
WordPress Wordpress 2.5
http://wordpress.org/latest.tar.gz
WordPress WordPress 2.2.1
-
WordPress Wordpress 2.5
http://wordpress.org/latest.tar.gz
WordPress WordPress 2.3.1
-
WordPress Wordpress 2.5
http://wordpress.org/latest.tar.gz
MandrakeSoft Corporate Server 3.0
-
Mandriva egroupware-1.0-0.RC3.1.2.C30mdk.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva egroupware-addressbook-1.0-0.RC3.1.2.C30mdk.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva egroupware-backup-1.0-0.RC3.1.2.C30mdk.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva egroupware-bookmarks-1.0-0.RC3.1.2.C30mdk.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva egroupware-calendar-1.0-0.RC3.1.2.C30mdk.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva egroupware-comic-1.0-0.RC3.1.2.C30mdk.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva egroupware-developer_tools-1.0-0.RC3.1.2.C30mdk.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva egroupware-email-1.0-0.RC3.1.2.C30mdk.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva egroupware-emailadmin-1.0-0.RC3.1.2.C30mdk.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva egroupware-etemplate-1.0-0.RC3.1.2.C30mdk.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva egroupware-felamimail-1.0-0.RC3.1.2.C30mdk.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva egroupware-filemanager-1.0-0.RC3.1.2.C30mdk.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva egroupware-forum-1.0-0.RC3.1.2.C30mdk.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva egroupware-ftp-1.0-0.RC3.1.2.C30mdk.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva egroupware-fudforum-1.0-0.RC3.1.2.C30mdk.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva egroupware-headlines-1.0-0.RC3.1.2.C30mdk.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva egroupware-infolog-1.0-0.RC3.1.2.C30mdk.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva egroupware-jinn-1.0-0.RC3.1.2.C30mdk.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva egroupware-messenger-1.0-0.RC3.1.2.C30mdk.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva egroupware-news_admin-1.0-0.RC3.1.2.C30mdk.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva egroupware-phpbrain-1.0-0.RC3.1.2.C30mdk.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva egroupware-phpldapadmin-1.0-0.RC3.1.2.C30mdk.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva egroupware-phpsysinfo-1.0-0.RC3.1.2.C30mdk.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva egroupware-polls-1.0-0.RC3.1.2.C30mdk.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva egroupware-projects-1.0-0.RC3.1.2.C30mdk.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva egroupware-registration-1.0-0.RC3.1.2.C30mdk.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva egroupware-sitemgr-1.0-0.RC3.1.2.C30mdk.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva egroupware-skel-1.0-0.RC3.1.2.C30mdk.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva egroupware-stocks-1.0-0.RC3.1.2.C30mdk.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva egroupware-tts-1.0-0.RC3.1.2.C30mdk.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva egroupware-wiki-1.0-0.RC3.1.2.C30mdk.noarch.rpm
http://www.mandriva.com/en/download/
References
kses Multiple Input Validation Vulnerabilities
References:
References:
- Dokeos Homepage (Dokeos)
- Dokeos Security Page (Dokeos)
- eGroupWare 1.4.003 Changelog (eGroupWare)
- eGroupWare Homepage (eGroupWare)
- FS#2312 - Security - KSES vulnerabilities (Dokeos)
- kses Project Page (kses)
- Moodle Homepage (Moodle)
- MSA-08-0008: KSES related issues (Moodle)
- Wordpress church_admin Plugin "id" Cross-Site Scripting Vulnerability (Sammy Forgit)
- Vulnerabilities in kses-based HTML filters ([email protected])