Zarafa Multiple Remote Vulnerabilities
BID:29122
Info
Zarafa Multiple Remote Vulnerabilities
| Bugtraq ID: | 29122 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 09 2008 12:00AM |
| Updated: | May 09 2008 06:55PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Zarafa Zarafa 6.01 Zarafa Zarafa 6.00 |
| Not Vulnerable: |
Zarafa Zarafa 6.02 |
Discussion
Zarafa Multiple Remote Vulnerabilities
Zarafa is prone to multiple remote HTML-injection vulnerabilities and denial-of-service vulnerabilities.
An attacker can exploit these issues to crash the affected application, execute arbitrary HTML and script code within the context of the affected website, potentially steal cookie-based authentication credentials, or control how the site is rendered to the user; other attacks are also possible.
These issues affect versions prior to Zarafa Script 6.02.
Zarafa is prone to multiple remote HTML-injection vulnerabilities and denial-of-service vulnerabilities.
An attacker can exploit these issues to crash the affected application, execute arbitrary HTML and script code within the context of the affected website, potentially steal cookie-based authentication credentials, or control how the site is rendered to the user; other attacks are also possible.
These issues affect versions prior to Zarafa Script 6.02.
Exploit / POC
Zarafa Multiple Remote Vulnerabilities
Attackers can exploit these issues by enticing an unsuspecting user to visit a malicious site.
Attackers can exploit these issues by enticing an unsuspecting user to visit a malicious site.
Solution / Fix
Zarafa Multiple Remote Vulnerabilities
Solution:
The vendor has released updates. Please see the references for more information.
Solution:
The vendor has released updates. Please see the references for more information.
References
Zarafa Multiple Remote Vulnerabilities
References:
References:
- Zarafa Changelog (Zarafa)
- Zarafa Homepage (Zarafa)