Horde MIME Attachment Filename Insufficient Filtering Cross-Site Scripting Vulnerability
BID:31110
Info
Horde MIME Attachment Filename Insufficient Filtering Cross-Site Scripting Vulnerability
| Bugtraq ID: | 31110 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-3823 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 10 2008 12:00AM |
| Updated: | Apr 13 2015 10:14PM |
| Credit: | Alexios Fakos |
| Vulnerable: |
TPLN TPLN 2.9 RevokeBB RevokeBB 1.0 RC11 phpMyFAQ phpMyFAQ 2.5 -dev Phour Phour r106 NoseRub NoseRub 0.5.2 NoseRub NoseRub 0.6 Mistralys SimpleSite 1.6.4 MAXdev MD-Pro 1.0.76 MAXdev MD-Pro 1.0.73 MAXdev MD-Pro 1.0.72 MAXdev MD-Pro 1.0821 MAXdev MD-Pro 1.081 Logicoder Logicoder r27 Horde Project Horde 3.2.1 Horde Project Horde 3.2 Horde Project Groupware Webmail Edition 1.1.2 Horde Project Groupware Webmail Edition 1.1.1 Horde Project Groupware 1.1.2 Horde Project Groupware 1.1.1 Flux CMS Popoon r22196 emuCMS emuCMS 0.3 emuCMS emuCMS 0.21 DeluxeBB DeluxeBB 1.0 5 DeluxeBB DeluxeBB 1.0 DeluxeBB DeluxeBB 1.2 DeluxeBB DeluxeBB 1.1 DeluxeBB DeluxeBB 1.09 DeluxeBB DeluxeBB 1.08 DeluxeBB DeluxeBB 1.07 DeluxeBB DeluxeBB 1.06 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 CakePHP CakePHP 1.2 7296 RC2 CakePHP CakePHP 1.1.8.3544 CakePHP CakePHP 1.1.7.3363 CakePHP CakePHP 1.1.6.3264 CakePHP CakePHP 1.1.5.3148 |
| Not Vulnerable: |
Horde Project Horde 3.2.2 Horde Project Groupware Webmail Edition 1.1.3 Horde Project Groupware 1.1.3 |
Discussion
Horde MIME Attachment Filename Insufficient Filtering Cross-Site Scripting Vulnerability
Horde Framework is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
This issue affects Horde Framework 3.2 through 3.2.1.
Note that additional products that use the Horde Framework may also be vulnerable.
Horde Framework is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
This issue affects Horde Framework 3.2 through 3.2.1.
Note that additional products that use the Horde Framework may also be vulnerable.
Exploit / POC
Horde MIME Attachment Filename Insufficient Filtering Cross-Site Scripting Vulnerability
The following example is available:
The following example is available:
Solution / Fix
Horde MIME Attachment Filename Insufficient Filtering Cross-Site Scripting Vulnerability
Solution:
Updates are available. Please see the references for more information.
Debian Linux 4.0 arm
Debian Linux 4.0 powerpc
Debian Linux 4.0 m68k
Debian Linux 4.0 amd64
Debian Linux 4.0 ia-32
Debian Linux 4.0 hppa
Debian Linux 4.0 sparc
Debian Linux 4.0 s/390
Debian Linux 4.0 alpha
Debian Linux 4.0
Flux CMS Popoon r22196
Debian Linux 4.0 mipsel
Horde Project Horde 3.2
Debian Linux 4.0 ia-64
Debian Linux 4.0 mips
Horde Project Horde 3.2.1
Solution:
Updates are available. Please see the references for more information.
Debian Linux 4.0 arm
-
Debian horde3_3.1.3-4etch4_all.deb
http://security.debian.org/pool/updates/main/h/horde3/horde3_3.1.3-4et ch4_all.deb
Debian Linux 4.0 powerpc
-
Debian horde3_3.1.3-4etch4_all.deb
http://security.debian.org/pool/updates/main/h/horde3/horde3_3.1.3-4et ch4_all.deb
Debian Linux 4.0 m68k
-
Debian horde3_3.1.3-4etch4_all.deb
http://security.debian.org/pool/updates/main/h/horde3/horde3_3.1.3-4et ch4_all.deb
Debian Linux 4.0 amd64
-
Debian horde3_3.1.3-4etch4_all.deb
http://security.debian.org/pool/updates/main/h/horde3/horde3_3.1.3-4et ch4_all.deb
Debian Linux 4.0 ia-32
-
Debian horde3_3.1.3-4etch4_all.deb
http://security.debian.org/pool/updates/main/h/horde3/horde3_3.1.3-4et ch4_all.deb
Debian Linux 4.0 hppa
-
Debian horde3_3.1.3-4etch4_all.deb
http://security.debian.org/pool/updates/main/h/horde3/horde3_3.1.3-4et ch4_all.deb
Debian Linux 4.0 sparc
-
Debian horde3_3.1.3-4etch4_all.deb
http://security.debian.org/pool/updates/main/h/horde3/horde3_3.1.3-4et ch4_all.deb
Debian Linux 4.0 s/390
-
Debian horde3_3.1.3-4etch4_all.deb
http://security.debian.org/pool/updates/main/h/horde3/horde3_3.1.3-4et ch4_all.deb
Debian Linux 4.0 alpha
-
Debian horde3_3.1.3-4etch4_all.deb
http://security.debian.org/pool/updates/main/h/horde3/horde3_3.1.3-4et ch4_all.deb
Debian Linux 4.0
-
Debian horde3_3.1.3-4etch4_all.deb
http://security.debian.org/pool/updates/main/h/horde3/horde3_3.1.3-4et ch4_all.deb
Flux CMS Popoon r22196
-
Flux CMS externalinput.php
http://svn.bitflux.ch/repos/public/popoon/trunk/classes/externalinput. php
Debian Linux 4.0 mipsel
-
Debian horde3_3.1.3-4etch4_all.deb
http://security.debian.org/pool/updates/main/h/horde3/horde3_3.1.3-4et ch4_all.deb
Horde Project Horde 3.2
-
Horde Text_Filter.patch
http://ocert.org/patches/2008-012/Text_Filter.patch
Debian Linux 4.0 ia-64
-
Debian horde3_3.1.3-4etch4_all.deb
http://security.debian.org/pool/updates/main/h/horde3/horde3_3.1.3-4et ch4_all.deb
Debian Linux 4.0 mips
-
Debian horde3_3.1.3-4etch4_all.deb
http://security.debian.org/pool/updates/main/h/horde3/horde3_3.1.3-4et ch4_all.deb
Horde Project Horde 3.2.1
-
Horde Text_Filter.patch
http://ocert.org/patches/2008-012/Text_Filter.patch
References
Horde MIME Attachment Filename Insufficient Filtering Cross-Site Scripting Vulnerability
References:
References:
- [announce] [SECURITY] Horde 3.2.2 (final) (Horde)
- [announce] [SECURITY] Horde Groupware Webmail Edition 1.1.3 (final) (Horde)
- [announce] Horde Groupware 1.1.3 (final) (Horde)
- Missed case in externalinput.php resulting in viable XSS attacks - fix available (Christian Stocker)
- n runs-SA-2008 006 Horde Cross-Site Scripting in filename MIME attachments (n.runs AG)
- Pandora Homepage (Pandora FMS Team)
- Popoon Homepage (Flux CMS)
- [oCERT-2008-012] Horde, Popoon frameworks common input sanitization errors (XSS) (Will Drewry
) - #2008-012 Horde, Popoon frameworks common input sanitization errors (XSS) (oCERT)