Multiple Horde Products Cross Site Scripting and HTML Injection Vulnerabilities
BID:51586
Info
Multiple Horde Products Cross Site Scripting and HTML Injection Vulnerabilities
| Bugtraq ID: | 51586 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-0909 CVE-2012-0791 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 20 2012 12:00AM |
| Updated: | Jun 04 2012 11:10AM |
| Credit: | Reported by the vendor |
| Vulnerable: |
SuSE openSUSE 11.4 Horde Project IMP 5.0.17 Horde Project IMP 5.0.16 Horde Project IMP 4.3.8 Horde Project IMP 4.3.7 Horde Project IMP 4.3.5 Horde Project IMP 4.3.4 Horde Project IMP 4.3.3 Horde Project IMP 4.3.2 Horde Project IMP 4.2.2 Horde Project IMP 4.2.1 Horde Project IMP 4.1.5 Horde Project IMP 4.1.4 Horde Project IMP 4.0.4 Horde Project IMP 4.0.3 Horde Project IMP 4.0.2 Horde Project IMP 4.0.1 Horde Project IMP 4.0 Horde Project IMP 5.0.4-Git Horde Project IMP 5.0.3 Horde Project IMP 5.0.2 Horde Project IMP 5.0.1 Horde Project IMP 5.0 Rc2 Horde Project IMP 5.0 Rc1 Horde Project IMP 5.0 Beta1 Horde Project IMP 5.0 Alpha1 Horde Project IMP 5.0 Horde Project IMP 4.3.9 Horde Project IMP 4.3.6 Horde Project IMP 4.3.1 Horde Project IMP 4.3 Horde Project IMP 4.2 Horde Project IMP 4.1.6 Horde Project IMP 4.1.3 Horde Project IMP 4.0 Horde Project Horde Groupware 4.0.5 Horde Project Horde 3.3.11 Horde Project Horde 3.3.10 Horde Project Horde 3.3.9 Horde Project Horde 3.3.8 Horde Project Horde 3.3.6 Horde Project Horde 3.3.5 Horde Project Horde 3.3.4 Horde Project Horde 3.3.3 Horde Project Horde 3.3.2 Horde Project Horde 3.3.1 Horde Project Horde 3.3 Horde Project Horde 3.2.5 Horde Project Horde 3.2.4 Horde Project Horde 3.2.3 Horde Project Horde 3.2.2 Horde Project Horde 3.2.1 Horde Project Horde 3.1.9 Horde Project Horde 3.1.8 Horde Project Horde 3.1.7 Horde Project Horde 3.1.6 Horde Project Horde 3.1.5 Horde Project Horde 3.1.4 Horde Project Horde 3.1.3 Horde Project Horde 3.1.2 Horde Project Horde 3.1.1 Horde Project Horde 3.0.11 Horde Project Horde 3.0.10 Horde Project Horde 3.0.9 Horde Project Horde 3.0.8 Horde Project Horde 3.0.7 Horde Project Horde 3.0.6 Horde Project Horde 3.0.4 -RC 2 Horde Project Horde 3.0.4 -RC 1 Horde Project Horde 3.0.4 Horde Project Horde 3.0.3 Horde Project Horde 3.0.2 Horde Project Horde 3.0.1 Horde Project Horde 3.0 Horde Project Horde 3.2 Horde Project Horde 3.1 Horde Project DIMP 0 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: |
Horde Project IMP 5.0.18 Horde Project IMP 4.3.11 Horde Project Horde Groupware 4.0.6 Horde Project Horde 3.3.13 Horde Project DIMP 1.1.8 |
Discussion
Multiple Horde Products Cross Site Scripting and HTML Injection Vulnerabilities
Multiple Horde products are prone to multiple cross-site scripting and HTML-injection vulnerabilities because they fail to properly sanitize user-supplied input before using it in dynamically generated content.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are possible.
Multiple Horde products are prone to multiple cross-site scripting and HTML-injection vulnerabilities because they fail to properly sanitize user-supplied input before using it in dynamically generated content.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are possible.
Exploit / POC
Multiple Horde Products Cross Site Scripting and HTML Injection Vulnerabilities
An attacker must trick an unsuspecting victim into following a malicious URI to exploit the cross-site scripting issues. An attacker can exploit the HTML-injection issues through a browser.
An attacker must trick an unsuspecting victim into following a malicious URI to exploit the cross-site scripting issues. An attacker can exploit the HTML-injection issues through a browser.
Solution / Fix
Multiple Horde Products Cross Site Scripting and HTML Injection Vulnerabilities
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Multiple Horde Products Cross Site Scripting and HTML Injection Vulnerabilities
References:
References:
- [announce] DIMP H4 (1.1.8) (final) (Horde Project)
- [announce] Horde 3.3.13 (final) (Horde Project)
- [announce] IMP H4 (4.3.11) (final) (Horde Project)
- Horde Groupware Release Notes 4.0.6 (Horde)
- Horde Homepage (Horde Project)
- Horde IMP Changelog (Horde Project)