Horde IMP Webmail 'fetchmailprefs.php' HTML Injection Vulnerability
BID:43515
Info
Horde IMP Webmail 'fetchmailprefs.php' HTML Injection Vulnerability
| Bugtraq ID: | 43515 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-3695 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 27 2010 12:00AM |
| Updated: | Mar 28 2011 10:47AM |
| Credit: | Moritz Naumann |
| Vulnerable: |
Horde Project IMP 4.3.7 Horde Project IMP 4.3.4 Horde Project IMP 4.3.3 Horde Project IMP 4.3.2 Horde Project IMP 4.2.2 Horde Project IMP 4.2.1 Horde Project IMP 4.1.5 Horde Project IMP 4.1.4 Horde Project IMP 4.0.4 Horde Project IMP 4.0.3 Horde Project IMP 4.0.2 Horde Project IMP 4.0.1 Horde Project IMP 4.0 Horde Project IMP 3.2.6 Horde Project IMP 3.2.5 Horde Project IMP 3.2.4 Horde Project IMP 3.2.3 Horde Project IMP 3.2.2 Horde Project IMP 3.2.1 Horde Project IMP 3.2 Horde Project IMP 3.1.2 Horde Project IMP 3.1 Horde Project IMP 3.0 Horde Project IMP 2.3.6 Horde Project IMP 2.3 Horde Project IMP 2.2.8 Horde Project IMP 2.2.7 Horde Project IMP 2.2.6 Horde Project IMP 2.2.5 Horde Project IMP 2.2.4 Horde Project IMP 2.2.3 Horde Project IMP 2.2.2 Horde Project IMP 2.2.1 Horde Project IMP 2.2 Horde Project IMP 2.0.9 Horde Project IMP 2.0.8 Horde Project IMP 2.0 Horde Horde IMP 4.1.3 Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 |
| Not Vulnerable: | |
Discussion
Horde IMP Webmail 'fetchmailprefs.php' HTML Injection Vulnerability
Horde IMP Webmail is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied data before it is used in dynamic content.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible.
Horde IMP 4.3.7 is affected; other versions may also be vulnerable.
Horde IMP Webmail is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied data before it is used in dynamic content.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible.
Horde IMP 4.3.7 is affected; other versions may also be vulnerable.
Exploit / POC
Horde IMP Webmail 'fetchmailprefs.php' HTML Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following example URI is available:
Attackers can use a browser to exploit this issue.
The following example URI is available:
Solution / Fix
Horde IMP Webmail 'fetchmailprefs.php' HTML Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Horde IMP Webmail 'fetchmailprefs.php' HTML Injection Vulnerability
References:
References:
- IMP Homepage (Horde Project)
- XSS in Horde IMP <=4.3.7, fetchmailprefs.php (Moritz Naumann
)