Multiple Horde Products Multiple Unspecified HTML Injection Vulnerabilities
BID:56541
Info
Multiple Horde Products Multiple Unspecified HTML Injection Vulnerabilities
| Bugtraq ID: | 56541 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-5566 CVE-2012-5567 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 15 2012 12:00AM |
| Updated: | Nov 23 2012 10:50PM |
| Credit: | Reported by the vendor |
| Vulnerable: |
Horde Project Kronolith 3.0.17 Horde Project Kronolith 3.0.16 Horde Project Horde Groupware 4.0.5 Horde Project Horde Groupware 4.0.6 Horde Horde Groupware Webmail Edition 4.0.8 Horde Horde Groupware 4.0.8 |
| Not Vulnerable: | |
Discussion
Multiple Horde Products Multiple Unspecified HTML Injection Vulnerabilities
Multiple Horde products including Groupware Webmail Edition, Groupware, and Kronolith are prone to multiple unspecified HTML-injection vulnerabilities because they fail to properly sanitize user-supplied input.
Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user; other attacks are also possible.
The following versions are vulnerable:
Groupware Webmail Edition versions prior to 4.0.9
Groupware versions prior to 4.0.9
Kronolith versions prior to 3.0.18
Multiple Horde products including Groupware Webmail Edition, Groupware, and Kronolith are prone to multiple unspecified HTML-injection vulnerabilities because they fail to properly sanitize user-supplied input.
Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user; other attacks are also possible.
The following versions are vulnerable:
Groupware Webmail Edition versions prior to 4.0.9
Groupware versions prior to 4.0.9
Kronolith versions prior to 3.0.18
Exploit / POC
Multiple Horde Products Multiple Unspecified HTML Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
Multiple Horde Products Multiple Unspecified HTML Injection Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Multiple Horde Products Multiple Unspecified HTML Injection Vulnerabilities
References:
References:
- Groupware Homepage (Horde Project)
- Kronolith Homepage (Horde Project)
- Pandora Homepage (Pandora FMS Team)
- Re: [oss-security] CVE Request -- kronolith: Two sets (3.0.17 && 3.0.18) of XSS (Kurt Seifried)
- [announce] Horde Groupware 4.0.9 (final) (Horde Project)
- [announce] Horde Groupware Webmail Edition 4.0.9 (final) (Horde Project)
- [announce] Kronolith H4 (3.0.18) (final) (Horde Project)