RoundCube Webmail '_mbox' Parameter Cross Site Scripting Vulnerability
BID:49229
Info
RoundCube Webmail '_mbox' Parameter Cross Site Scripting Vulnerability
| Bugtraq ID: | 49229 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-2937 CVE-2011-2937 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 18 2011 12:00AM |
| Updated: | Apr 16 2015 05:48PM |
| Credit: | <br>abyszko |
| Vulnerable: |
Roundcube Webmail 0.5.1 Roundcube Webmail 0.5 Rc Roundcube Webmail 0.5 Beta Roundcube Webmail 0.5 Roundcube Webmail 0.4.2 Roundcube Webmail 0.4.1 Roundcube Webmail 0.4 Beta Roundcube Webmail 0.4 Roundcube Webmail 0.3.1 Roundcube Webmail 0.3 Rc1 Roundcube Webmail 0.3 Beta Roundcube Webmail 0.3 Roundcube Webmail 0.2.1 Roundcube Webmail 0.2 Beta Roundcube Webmail 0.2 alpha Roundcube Webmail 0.2 Roundcube Webmail 0.1.1 Roundcube Webmail 0.1 Rc2 Roundcube Webmail 0.1 Rc1 Roundcube Webmail 0.1 Beta2 Roundcube Webmail 0.1 Beta Roundcube Webmail 0.1 Alpha Roundcube Webmail 0.1 Round Cube RoundCube Webmail 0.5.3 Round Cube RoundCube Webmail 0.5.1 Round Cube RoundCube Webmail 0.3.1 Round Cube RoundCube Webmail 0.2.2 Round Cube RoundCube Webmail 0.5 Round Cube RoundCube Webmail 0.4-beta Round Cube RoundCube Webmail 0.3 stable Round Cube RoundCube Webmail 0.2-stable Round Cube RoundCube Webmail 0.2-3 beta Round Cube RoundCube Webmail 0.2-1 alpha Round Cube RoundCube Webmail 0.1rc2 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Apple Mac Os X Server 10.7.2 Apple Mac Os X Server 10.7.1 Apple Mac Os X Server 10.7 Apple Mac Os X 10.7.2 Apple Mac Os X 10.7.1 |
| Not Vulnerable: |
Round Cube RoundCube Webmail 0.5.4 Apple Mac Os X Server 10.7.3 Apple Mac Os X 10.7.3 |
Discussion
RoundCube Webmail '_mbox' Parameter Cross Site Scripting Vulnerability
RoundCube Webmail is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to RoundCube Webmail 0.5.4 are vulnerable.
RoundCube Webmail is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to RoundCube Webmail 0.5.4 are vulnerable.
Exploit / POC
RoundCube Webmail '_mbox' Parameter Cross Site Scripting Vulnerability
Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
RoundCube Webmail '_mbox' Parameter Cross Site Scripting Vulnerability
Solution:
The vendor released an update. Please see the references for details.
Apple Mac Os X 10.7.2
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Enterprise Server 5
Apple Mac Os X Server 10.7.1
Apple Mac Os X Server 10.7.2
Apple Mac Os X 10.7.1
Apple Mac Os X Server 10.7
Solution:
The vendor released an update. Please see the references for details.
Apple Mac Os X 10.7.2
-
Apple MacOSXUpd10.7.3.dmg
For OS X Lion v10.7.2
http://www.apple.com/support/downloads/
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva roundcubemail-0.7.2-0.1mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5
-
Mandriva roundcubemail-0.7.2-0.1mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/
Apple Mac Os X Server 10.7.1
-
Apple MacOSXServerUpdCombo10.7.3.dmg
For OS X Lion Server v10.7 and v10.7.1
http://www.apple.com/support/downloads/
Apple Mac Os X Server 10.7.2
-
Apple MacOSXServerUpd10.7.3.dmg
For OS X Lion Server v10.7.2
http://www.apple.com/support/downloads/
Apple Mac Os X 10.7.1
-
Apple MacOSXUpdCombo10.7.3.dmg
For OS X Lion v10.7 and v10.7.1
http://www.apple.com/support/downloads/
Apple Mac Os X Server 10.7
-
Apple MacOSXServerUpdCombo10.7.3.dmg
For OS X Lion Server v10.7 and v10.7.1
http://www.apple.com/support/downloads/
References
RoundCube Webmail '_mbox' Parameter Cross Site Scripting Vulnerability
References:
References:
- RoundCube Webmail Homepage (RoundCube)
- source: tags/roundcubemail/v0.5.4/CHANGELOG @ 5061 (Round Cube)
- XSS within _mbox parameter (Round Cube)