Horde Security Bypass and HTML Injection Vulnerabilities
BID:47708
Info
Horde Security Bypass and HTML Injection Vulnerabilities
| Bugtraq ID: | 47708 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 04 2011 12:00AM |
| Updated: | May 04 2011 12:00AM |
| Credit: | The vendor reported these issues. |
| Vulnerable: |
Horde Project Horde 4.0.1 |
| Not Vulnerable: |
Horde Project Horde 4.0.2 |
Discussion
Horde Security Bypass and HTML Injection Vulnerabilities
Horde is prone to a security-bypass vulnerability and an HTML-injection vulnerability because it fails to properly validate user-supplied input.
An attacker may leverage the HTML-injection issue to inject hostile HTML and script code that would run in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. The attacker may leverage the security-bypass issue to bypass certain security restrictions and perform unauthorized actions in the affected application.
Horde 4.0.1 is vulnerable; other versions may also be affected.
Horde is prone to a security-bypass vulnerability and an HTML-injection vulnerability because it fails to properly validate user-supplied input.
An attacker may leverage the HTML-injection issue to inject hostile HTML and script code that would run in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. The attacker may leverage the security-bypass issue to bypass certain security restrictions and perform unauthorized actions in the affected application.
Horde 4.0.1 is vulnerable; other versions may also be affected.
Exploit / POC
Horde Security Bypass and HTML Injection Vulnerabilities
Attackers can use a browser to exploit the issues.
Attackers can use a browser to exploit the issues.
Solution / Fix
Horde Security Bypass and HTML Injection Vulnerabilities
Solution:
The vendor has released updates. Please see the references for details.
Solution:
The vendor has released updates. Please see the references for details.
References
Horde Security Bypass and HTML Injection Vulnerabilities
References:
References:
- Horde Changes by Release (Horde)
- Vendor Homepage (Horde)