Horde Products Local File Include and Cross Site Scripting Vulnerabilities
BID:33491
Info
Horde Products Local File Include and Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 33491 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-0932 CVE-2009-0931 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 27 2009 12:00AM |
| Updated: | Apr 13 2015 09:55PM |
| Credit: | Gunnar Wrobel |
| Vulnerable: |
Horde Project Horde 3.3.2 Horde Project Horde 3.3.1 Horde Project Horde 3.3 Horde Project Horde 3.2.3 Horde Project Horde 3.2.2 Horde Project Horde 3.2.1 Horde Project Groupware 1.1.4 Horde Project Groupware 1.1.3 Horde Project Groupware 1.1.2 Horde Project Groupware 1.1.1 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 armel Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
Horde Project Horde 3.3.3 Horde Project Horde 3.2.4 Horde Project Groupware 1.1.5 |
Discussion
Horde Products Local File Include and Cross Site Scripting Vulnerabilities
Horde products are prone to a local file-include vulnerability and a cross-site scripting vulnerability because they fail to properly sanitize user-supplied input.
An attacker can exploit the local file-include vulnerability using directory-traversal strings to view and execute local files within the context of the webserver process. Information harvested may aid in further attacks.
The attacker may leverage the cross-site scripting issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
The issues affect versions prior to the following:
Horde 3.2.4 and 3.3.3
Horde Groupware 1.1.5
Horde products are prone to a local file-include vulnerability and a cross-site scripting vulnerability because they fail to properly sanitize user-supplied input.
An attacker can exploit the local file-include vulnerability using directory-traversal strings to view and execute local files within the context of the webserver process. Information harvested may aid in further attacks.
The attacker may leverage the cross-site scripting issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
The issues affect versions prior to the following:
Horde 3.2.4 and 3.3.3
Horde Groupware 1.1.5
Exploit / POC
Horde Products Local File Include and Cross Site Scripting Vulnerabilities
Attackers can exploit these issues via a browser.
Attackers can exploit these issues via a browser.
Solution / Fix
Horde Products Local File Include and Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Debian Linux 4.0 amd64
Debian Linux 4.0 ia-32
Debian Linux 4.0 arm
Debian Linux 4.0 hppa
Debian Linux 4.0 sparc
Debian Linux 4.0 s/390
Debian Linux 4.0 powerpc
Debian Linux 4.0 alpha
Debian Linux 4.0 armel
Debian Linux 4.0 m68k
Debian Linux 4.0
Debian Linux 4.0 mipsel
Debian Linux 4.0 ia-64
Debian Linux 4.0 mips
Horde Project Groupware 1.1.4
Horde Project Horde 3.3.2
Solution:
Updates are available. Please see the references for more information.
Debian Linux 4.0 amd64
-
Debian horde3_3.1.3-4etch5_all.deb
http://security.debian.org/pool/updates/main/h/horde3/horde3_3.1.3-4et ch5_all.deb
Debian Linux 4.0 ia-32
-
Debian horde3_3.1.3-4etch5_all.deb
http://security.debian.org/pool/updates/main/h/horde3/horde3_3.1.3-4et ch5_all.deb
Debian Linux 4.0 arm
-
Debian horde3_3.1.3-4etch5_all.deb
http://security.debian.org/pool/updates/main/h/horde3/horde3_3.1.3-4et ch5_all.deb
Debian Linux 4.0 hppa
-
Debian horde3_3.1.3-4etch5_all.deb
http://security.debian.org/pool/updates/main/h/horde3/horde3_3.1.3-4et ch5_all.deb
Debian Linux 4.0 sparc
-
Debian horde3_3.1.3-4etch5_all.deb
http://security.debian.org/pool/updates/main/h/horde3/horde3_3.1.3-4et ch5_all.deb
Debian Linux 4.0 s/390
-
Debian horde3_3.1.3-4etch5_all.deb
http://security.debian.org/pool/updates/main/h/horde3/horde3_3.1.3-4et ch5_all.deb
Debian Linux 4.0 powerpc
-
Debian horde3_3.1.3-4etch5_all.deb
http://security.debian.org/pool/updates/main/h/horde3/horde3_3.1.3-4et ch5_all.deb
Debian Linux 4.0 alpha
-
Debian horde3_3.1.3-4etch5_all.deb
http://security.debian.org/pool/updates/main/h/horde3/horde3_3.1.3-4et ch5_all.deb
Debian Linux 4.0 armel
-
Debian horde3_3.1.3-4etch5_all.deb
http://security.debian.org/pool/updates/main/h/horde3/horde3_3.1.3-4et ch5_all.deb
Debian Linux 4.0 m68k
-
Debian horde3_3.1.3-4etch5_all.deb
http://security.debian.org/pool/updates/main/h/horde3/horde3_3.1.3-4et ch5_all.deb
Debian Linux 4.0
-
Debian horde3_3.1.3-4etch5_all.deb
http://security.debian.org/pool/updates/main/h/horde3/horde3_3.1.3-4et ch5_all.deb
Debian Linux 4.0 mipsel
-
Debian horde3_3.1.3-4etch5_all.deb
http://security.debian.org/pool/updates/main/h/horde3/horde3_3.1.3-4et ch5_all.deb
Debian Linux 4.0 ia-64
-
Debian horde3_3.1.3-4etch5_all.deb
http://security.debian.org/pool/updates/main/h/horde3/horde3_3.1.3-4et ch5_all.deb
Debian Linux 4.0 mips
-
Debian horde3_3.1.3-4etch5_all.deb
http://security.debian.org/pool/updates/main/h/horde3/horde3_3.1.3-4et ch5_all.deb
Horde Project Groupware 1.1.4
-
Horde horde-groupware-1.1.5.tar.gz
http://ftp.horde.org/pub/horde-groupware/horde-groupware-1.1.5.tar.gz
Horde Project Horde 3.3.2
-
Horde horde-3.3.3.tar.gz
http://ftp.horde.org/pub/horde/horde-3.3.3.tar.gz
References
Horde Products Local File Include and Cross Site Scripting Vulnerabilities
References:
References:
- [announce] Horde 3.2.4 (final) (Horde)
- [announce] Horde 3.3.3 (final) (Horde)
- [announce] Horde Groupware 1.1.5 (final) (Horde)
- Pandora Homepage (Pandora FMS Team)