Community
Advisories
Horde Products MIME Library and HTML Message Script Insertion Vulnerabilities
Secunia Advisory SA31842Horde Products MIME Library and HTML Message Script Insertion Vulnerabilities
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
Some vulnerabilities have been reported in various Horde products, which can be exploited by malicious people to conduct script insertion attacks. 1) Input via MIME attachment linking is not properly sanitised in the MIME library before being used. This can be exploited to execute arbitrary HTML and script code in a user's browser session if e.g. a malicious email is viewed. This vulnerability is reported in versions prior to Horde Groupware Webmail Edition version 1.1.3, Horde Groupware version 1.1.3, and Horde Application Framework version 3.2.2. 2) Input containing the "/" character as replacement for a space character is not properly sanitised. This can be exploited to execute arbitrary HTML and script code in a user's browser session if e.g. a malicious HTML email is viewed. Successful exploitation requires that the victim's browser handles "/" as space characters. This vulnerability is reported in versions prior to Horde Groupware Webmail Edition version 1.0.8 and 1.1.3, Horde Groupware version 1.0.7 and 1.1.3, Horde Application Framework version 3.1.9 and 3.2.2. Solution Provided and/or discovered by Deep Links Do you have additional information related to this advisory?Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||
155 views | ![]() |
| Gentoo update for sarg | |
212 views | ![]() |
| Debian update for freetype | |