Horde 'Passwd' Module Cross Site Scripting Vulnerability
BID:35573
Info
Horde 'Passwd' Module Cross Site Scripting Vulnerability
| Bugtraq ID: | 35573 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-2360 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2009 12:00AM |
| Updated: | Sep 14 2009 05:31PM |
| Credit: | Reported by the vendor |
| Vulnerable: |
Horde Project Passwd 3.1 Gentoo Linux Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 armel Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
Horde Project Passwd 3.1.1 |
Discussion
Horde 'Passwd' Module Cross Site Scripting Vulnerability
The Horde 'Passwd' module is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
Versions prior to Horde 'Passwd' 3.1.1 are vulnerable.
The Horde 'Passwd' module is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
Versions prior to Horde 'Passwd' 3.1.1 are vulnerable.
Exploit / POC
Horde 'Passwd' Module Cross Site Scripting Vulnerability
Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
The following proof-of-concept URI is available:
http://www.example.com/horde/passwd/main.php?backend="><script>alert('XSS')</script>&userid=stevejobs&return_to=&oldpassword=foo&newpassword0=foo&newpassword1=foo&submit=Change%20Password
Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
The following proof-of-concept URI is available:
http://www.example.com/horde/passwd/main.php?backend="><script>alert('XSS')</script>&userid=stevejobs&return_to=&oldpassword=foo&newpassword0=foo&newpassword1=foo&submit=Change%20Password
Solution / Fix
Horde 'Passwd' Module Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references for more information.
Debian Linux 4.0 amd64
Debian Linux 4.0 ia-32
Debian Linux 4.0 arm
Debian Linux 5.0 hppa
Debian Linux 5.0 ia-64
Debian Linux 4.0 hppa
Debian Linux 4.0 sparc
Debian Linux 4.0 s/390
Debian Linux 5.0 m68k
Debian Linux 5.0 arm
Debian Linux 4.0 powerpc
Debian Linux 4.0 alpha
Debian Linux 4.0 armel
Debian Linux 5.0 armel
Debian Linux 4.0 m68k
Debian Linux 5.0
Debian Linux 4.0
Debian Linux 4.0 mipsel
Debian Linux 5.0 amd64
Debian Linux 5.0 alpha
Debian Linux 5.0 ia-32
Debian Linux 5.0 mips
Debian Linux 5.0 s/390
Debian Linux 5.0 mipsel
Debian Linux 5.0 powerpc
Debian Linux 4.0 ia-64
Debian Linux 4.0 mips
Debian Linux 5.0 sparc
Solution:
Updates are available. Please see the references for more information.
Debian Linux 4.0 amd64
-
Debian sork-passwd-h3_3.0-2+etch1_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+etch1_all.deb -
Debian sork-passwd-h3_3.0-2+etch2_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+etch2_all.deb
Debian Linux 4.0 ia-32
-
Debian sork-passwd-h3_3.0-2+etch1_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+etch1_all.deb -
Debian sork-passwd-h3_3.0-2+etch2_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+etch2_all.deb
Debian Linux 4.0 arm
-
Debian sork-passwd-h3_3.0-2+etch1_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+etch1_all.deb -
Debian sork-passwd-h3_3.0-2+etch2_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+etch2_all.deb
Debian Linux 5.0 hppa
-
Debian sork-passwd-h3_3.0-2+lenny1_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+lenny1_all.deb -
Debian sork-passwd-h3_3.0-2+lenny2_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+lenny2_all.deb
Debian Linux 5.0 ia-64
-
Debian sork-passwd-h3_3.0-2+lenny1_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+lenny1_all.deb -
Debian sork-passwd-h3_3.0-2+lenny2_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+lenny2_all.deb
Debian Linux 4.0 hppa
-
Debian sork-passwd-h3_3.0-2+etch1_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+etch1_all.deb -
Debian sork-passwd-h3_3.0-2+etch2_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+etch2_all.deb
Debian Linux 4.0 sparc
-
Debian sork-passwd-h3_3.0-2+etch1_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+etch1_all.deb -
Debian sork-passwd-h3_3.0-2+etch2_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+etch2_all.deb
Debian Linux 4.0 s/390
-
Debian sork-passwd-h3_3.0-2+etch1_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+etch1_all.deb -
Debian sork-passwd-h3_3.0-2+etch2_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+etch2_all.deb
Debian Linux 5.0 m68k
-
Debian sork-passwd-h3_3.0-2+lenny1_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+lenny1_all.deb -
Debian sork-passwd-h3_3.0-2+lenny2_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+lenny2_all.deb
Debian Linux 5.0 arm
-
Debian sork-passwd-h3_3.0-2+lenny1_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+lenny1_all.deb -
Debian sork-passwd-h3_3.0-2+lenny2_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+lenny2_all.deb
Debian Linux 4.0 powerpc
-
Debian sork-passwd-h3_3.0-2+etch1_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+etch1_all.deb -
Debian sork-passwd-h3_3.0-2+etch2_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+etch2_all.deb
Debian Linux 4.0 alpha
-
Debian sork-passwd-h3_3.0-2+etch1_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+etch1_all.deb -
Debian sork-passwd-h3_3.0-2+etch2_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+etch2_all.deb
Debian Linux 4.0 armel
-
Debian sork-passwd-h3_3.0-2+etch1_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+etch1_all.deb -
Debian sork-passwd-h3_3.0-2+etch2_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+etch2_all.deb
Debian Linux 5.0 armel
-
Debian sork-passwd-h3_3.0-2+lenny1_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+lenny1_all.deb -
Debian sork-passwd-h3_3.0-2+lenny2_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+lenny2_all.deb
Debian Linux 4.0 m68k
-
Debian sork-passwd-h3_3.0-2+etch1_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+etch1_all.deb -
Debian sork-passwd-h3_3.0-2+etch2_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+etch2_all.deb
Debian Linux 5.0
-
Debian sork-passwd-h3_3.0-2+lenny1_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+lenny1_all.deb -
Debian sork-passwd-h3_3.0-2+lenny2_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+lenny2_all.deb
Debian Linux 4.0
-
Debian sork-passwd-h3_3.0-2+etch1_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+etch1_all.deb -
Debian sork-passwd-h3_3.0-2+etch2_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+etch2_all.deb
Debian Linux 4.0 mipsel
-
Debian sork-passwd-h3_3.0-2+etch1_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+etch1_all.deb -
Debian sork-passwd-h3_3.0-2+etch2_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+etch2_all.deb
Debian Linux 5.0 amd64
-
Debian sork-passwd-h3_3.0-2+lenny1_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+lenny1_all.deb -
Debian sork-passwd-h3_3.0-2+lenny2_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+lenny2_all.deb
Debian Linux 5.0 alpha
-
Debian sork-passwd-h3_3.0-2+lenny1_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+lenny1_all.deb -
Debian sork-passwd-h3_3.0-2+lenny2_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+lenny2_all.deb
Debian Linux 5.0 ia-32
-
Debian sork-passwd-h3_3.0-2+lenny1_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+lenny1_all.deb -
Debian sork-passwd-h3_3.0-2+lenny2_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+lenny2_all.deb
Debian Linux 5.0 mips
-
Debian sork-passwd-h3_3.0-2+lenny1_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+lenny1_all.deb -
Debian sork-passwd-h3_3.0-2+lenny2_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+lenny2_all.deb
Debian Linux 5.0 s/390
-
Debian sork-passwd-h3_3.0-2+lenny1_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+lenny1_all.deb -
Debian sork-passwd-h3_3.0-2+lenny2_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+lenny2_all.deb
Debian Linux 5.0 mipsel
-
Debian sork-passwd-h3_3.0-2+lenny1_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+lenny1_all.deb -
Debian sork-passwd-h3_3.0-2+lenny2_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+lenny2_all.deb
Debian Linux 5.0 powerpc
-
Debian sork-passwd-h3_3.0-2+lenny1_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+lenny1_all.deb -
Debian sork-passwd-h3_3.0-2+lenny2_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+lenny2_all.deb
Debian Linux 4.0 ia-64
-
Debian sork-passwd-h3_3.0-2+etch1_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+etch1_all.deb -
Debian sork-passwd-h3_3.0-2+etch2_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+etch2_all.deb
Debian Linux 4.0 mips
-
Debian sork-passwd-h3_3.0-2+etch1_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+etch1_all.deb -
Debian sork-passwd-h3_3.0-2+etch2_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+etch2_all.deb
Debian Linux 5.0 sparc
-
Debian sork-passwd-h3_3.0-2+lenny1_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+lenny1_all.deb -
Debian sork-passwd-h3_3.0-2+lenny2_all.deb
http://security.debian.org/pool/updates/main/s/sork-passwd-h3/sork-pas swd-h3_3.0-2+lenny2_all.deb
References
Horde 'Passwd' Module Cross Site Scripting Vulnerability
References:
References:
- [#8398] Cross Site Scripting Vulnerability (Horde Project)
- Pandora Homepage (Pandora FMS Team)
- Passwd Product Page (Horde Project)
- Passwd H3 (3.1.1) (final) (Chuck Hagenbuch)