Horde Webmail 'addevent.php' Cross-Site Scripting Vulnerability
BID:28898
Info
Horde Webmail 'addevent.php' Cross-Site Scripting Vulnerability
| Bugtraq ID: | 28898 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1974 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 23 2008 12:00AM |
| Updated: | May 07 2015 05:29PM |
| Credit: | Aria-Security Team |
| Vulnerable: |
Redhat Fedora 7 Horde Project Kronolith 2.1.7 Horde Project Kronolith 2.1.4 Horde Project Groupware Webmail Edition 1.0.6 Horde Project Groupware 1.0.5 |
| Not Vulnerable: |
Horde Project Groupware Webmail Edition 1.1.1 Horde Project Groupware Webmail Edition 1.0.7 Horde Project Groupware 1.1.1 Horde Project Groupware 1.0.6 |
Discussion
Horde Webmail 'addevent.php' Cross-Site Scripting Vulnerability
Horde Webmail is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials.
This issue affects Kronolith 2.1.7. The vulnerable Kronolith versions are included in Horde Groupware 1.0.5 and Horde Groupware Webmail Edition 1.0.6.
Horde Webmail is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials.
This issue affects Kronolith 2.1.7. The vulnerable Kronolith versions are included in Horde Groupware 1.0.5 and Horde Groupware Webmail Edition 1.0.6.
Exploit / POC
Horde Webmail 'addevent.php' Cross-Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
The following proof of concept is available:
http://www.example.com/horde/kronolith/addevent.php?timestamp=1208932200&url=[xss]
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
The following proof of concept is available:
http://www.example.com/horde/kronolith/addevent.php?timestamp=1208932200&url=[xss]
Solution / Fix
Horde Webmail 'addevent.php' Cross-Site Scripting Vulnerability
Solution:
Fixes are available. Please see the references for more information.
Horde Project Groupware 1.0.5
Horde Project Groupware Webmail Edition 1.0.6
Solution:
Fixes are available. Please see the references for more information.
Horde Project Groupware 1.0.5
-
Horde horde-groupware-1.0.6.tar.gz
http://ftp.horde.org/pub/horde-groupware/horde-groupware-1.0.6.tar.gz
Horde Project Groupware Webmail Edition 1.0.6
-
Horde horde-webmail-1.0.7.tar.gz
http://ftp.horde.org/pub/horde-webmail/horde-webmail-1.0.7.tar.gz
References
Horde Webmail 'addevent.php' Cross-Site Scripting Vulnerability
References:
References:
- [announce] Horde Groupware 1.0.6 (final) (Horde)
- [announce] Horde Groupware Webmail Edition 1.0.7 (final) (Horde)
- Horde Groupware Changelog (Horde)
- Pandora Homepage (Pandora FMS Team)
- Horde Webmail XSS [Aria-Security] ([email protected])