Horde IMP Webmail Client Cross Site Scripting And HTML Injection Vulnerabilities
BID:33492
Info
Horde IMP Webmail Client Cross Site Scripting And HTML Injection Vulnerabilities
| Bugtraq ID: | 33492 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-0930 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 27 2009 12:00AM |
| Updated: | Apr 01 2010 11:32AM |
| Credit: | Gunnar Wrobel |
| Vulnerable: |
Red Hat Fedora 11 Horde Project IMP 4.3.2 Horde Project IMP 4.2.1 Horde Project IMP 4.1.5 Horde Project IMP 4.1.4 Horde Project IMP 4.0.4 Horde Project IMP 4.0.3 Horde Project IMP 4.0.2 Horde Project IMP 4.0.1 Horde Project IMP 4.0 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 armel Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
Horde Project IMP 4.3.3 Horde Project IMP 4.2.2 |
Discussion
Horde IMP Webmail Client Cross Site Scripting And HTML Injection Vulnerabilities
Horde IMP Webmail Client is prone to multiple cross-site scripting and HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible.
Versions prior to IMP 4.2.2 and 4.3.3 are affected.
Horde IMP Webmail Client is prone to multiple cross-site scripting and HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible.
Versions prior to IMP 4.2.2 and 4.3.3 are affected.
Exploit / POC
Horde IMP Webmail Client Cross Site Scripting And HTML Injection Vulnerabilities
Attackers can use a browser to exploit these issues. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
Attackers can use a browser to exploit these issues. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
Horde IMP Webmail Client Cross Site Scripting And HTML Injection Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Debian Linux 4.0 amd64
Debian Linux 4.0 ia-32
Debian Linux 4.0 arm
Debian Linux 4.0 hppa
Debian Linux 4.0 sparc
Debian Linux 4.0 s/390
Debian Linux 4.0 powerpc
Debian Linux 4.0 alpha
Debian Linux 4.0 armel
Debian Linux 4.0 m68k
Debian Linux 4.0
Debian Linux 4.0 mipsel
Debian Linux 4.0 ia-64
Debian Linux 4.0 mips
Solution:
Updates are available. Please see the references for more information.
Debian Linux 4.0 amd64
-
Debian imp4_4.1.3-4etch1_all.deb
http://security.debian.org/pool/updates/main/i/imp4/imp4_4.1.3-4etch1_ all.deb
Debian Linux 4.0 ia-32
-
Debian imp4_4.1.3-4etch1_all.deb
http://security.debian.org/pool/updates/main/i/imp4/imp4_4.1.3-4etch1_ all.deb
Debian Linux 4.0 arm
-
Debian imp4_4.1.3-4etch1_all.deb
http://security.debian.org/pool/updates/main/i/imp4/imp4_4.1.3-4etch1_ all.deb
Debian Linux 4.0 hppa
-
Debian imp4_4.1.3-4etch1_all.deb
http://security.debian.org/pool/updates/main/i/imp4/imp4_4.1.3-4etch1_ all.deb
Debian Linux 4.0 sparc
-
Debian imp4_4.1.3-4etch1_all.deb
http://security.debian.org/pool/updates/main/i/imp4/imp4_4.1.3-4etch1_ all.deb
Debian Linux 4.0 s/390
-
Debian imp4_4.1.3-4etch1_all.deb
http://security.debian.org/pool/updates/main/i/imp4/imp4_4.1.3-4etch1_ all.deb
Debian Linux 4.0 powerpc
-
Debian imp4_4.1.3-4etch1_all.deb
http://security.debian.org/pool/updates/main/i/imp4/imp4_4.1.3-4etch1_ all.deb
Debian Linux 4.0 alpha
-
Debian imp4_4.1.3-4etch1_all.deb
http://security.debian.org/pool/updates/main/i/imp4/imp4_4.1.3-4etch1_ all.deb
Debian Linux 4.0 armel
-
Debian imp4_4.1.3-4etch1_all.deb
http://security.debian.org/pool/updates/main/i/imp4/imp4_4.1.3-4etch1_ all.deb
Debian Linux 4.0 m68k
-
Debian imp4_4.1.3-4etch1_all.deb
http://security.debian.org/pool/updates/main/i/imp4/imp4_4.1.3-4etch1_ all.deb
Debian Linux 4.0
-
Debian imp4_4.1.3-4etch1_all.deb
http://security.debian.org/pool/updates/main/i/imp4/imp4_4.1.3-4etch1_ all.deb
Debian Linux 4.0 mipsel
-
Debian imp4_4.1.3-4etch1_all.deb
http://security.debian.org/pool/updates/main/i/imp4/imp4_4.1.3-4etch1_ all.deb
Debian Linux 4.0 ia-64
-
Debian imp4_4.1.3-4etch1_all.deb
http://security.debian.org/pool/updates/main/i/imp4/imp4_4.1.3-4etch1_ all.deb
Debian Linux 4.0 mips
-
Debian imp4_4.1.3-4etch1_all.deb
http://security.debian.org/pool/updates/main/i/imp4/imp4_4.1.3-4etch1_ all.deb
References
Horde IMP Webmail Client Cross Site Scripting And HTML Injection Vulnerabilities
References:
References:
- [announce] IMP 4.2.2 (final) (Horde Project)
- IMP Homepage (Horde Project)