Horde Application Framework 'icon_browser.php' Cross-Site Scripting Vulnerability
BID:43001
Info
Horde Application Framework 'icon_browser.php' Cross-Site Scripting Vulnerability
| Bugtraq ID: | 43001 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-3077 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 06 2010 12:00AM |
| Updated: | May 07 2015 05:02PM |
| Credit: | Moritz Naumann |
| Vulnerable: |
Horde Project Horde 3.3.8 Horde Project Horde 3.3.6 Horde Project Horde 3.3.5 Horde Project Horde 3.3.4 Horde Project Horde 3.3.3 Horde Project Horde 3.3.2 Horde Project Horde 3.3.1 Horde Project Horde 3.3 Horde Project Horde 3.2.5 Horde Project Horde 3.2.4 Horde Project Horde 3.2.3 Horde Project Horde 3.2.2 Horde Project Horde 3.2.1 Horde Project Horde 3.1.9 Horde Project Horde 3.1.8 Horde Project Horde 3.1.7 Horde Project Horde 3.1.6 Horde Project Horde 3.1.5 Horde Project Horde 3.1.4 Horde Project Horde 3.1.3 Horde Project Horde 3.1.2 Horde Project Horde 3.1.1 Horde Project Horde 3.0.11 Horde Project Horde 3.0.10 Horde Project Horde 3.0.9 Horde Project Horde 3.0.8 Horde Project Horde 3.0.7 Horde Project Horde 3.0.6 Horde Project Horde 3.0.4 -RC 2 Horde Project Horde 3.0.4 -RC 1 Horde Project Horde 3.0.4 Horde Project Horde 3.0.3 Horde Project Horde 3.0.2 Horde Project Horde 3.0.1 Horde Project Horde 3.0 Horde Project Horde 3.2 Horde Project Horde 3.1 |
| Not Vulnerable: |
Horde Project Horde 3.3.9 |
Discussion
Horde Application Framework 'icon_browser.php' Cross-Site Scripting Vulnerability
Horde Application Framework is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
This issue affects versions prior to and including Horde 3.3.8.
Note that additional products that use the Horde framework may also be vulnerable.
Horde Application Framework is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
This issue affects versions prior to and including Horde 3.3.8.
Note that additional products that use the Horde framework may also be vulnerable.
Exploit / POC
Horde Application Framework 'icon_browser.php' Cross-Site Scripting Vulnerability
An attacker can exploit this issue by enticing a user to visit a malicious site.
The following example URI is available:
http://www.example.com/util/icon_browser.php?subdir=[xss]&app=horde
An attacker can exploit this issue by enticing a user to visit a malicious site.
The following example URI is available:
http://www.example.com/util/icon_browser.php?subdir=[xss]&app=horde
Solution / Fix
Horde Application Framework 'icon_browser.php' Cross-Site Scripting Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Horde Application Framework 'icon_browser.php' Cross-Site Scripting Vulnerability
References:
References:
- Diff for horde/util/icon_browser.php between version a978a35[...] and 9342add[.. (Horde)
- Pandora Homepage (Pandora FMS Team)
- XSS in Horde Application Framework <=3.3.8, icon_browser.php (Moritz Naumann
) - [announce] Horde 3.3.9 (final) (Horde Project)