Horde IMP Webmail Client is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
Credit:
The information has been provided by Aboud-el .
The original article can be found at: http://www.securityfocus.com/bid/53435
Vulnerable Systems:
* Horde Project IMP 5.0.18
* Horde Project IMP 5.0.17
* Horde Project IMP 5.0.16
* Horde Project IMP 5.0.4-Git
* Horde Project IMP 5.0.3
* Horde Project IMP 5.0.2
* Horde Project IMP 5.0.1
* Horde Project IMP 5.0 Rc2
* Horde Project IMP 5.0 Rc1
* Horde Project IMP 5.0 Beta1
* Horde Project IMP 5.0 Alpha1
* Horde Project IMP 5.0
* Horde Horde Groupware Webmail Edition 4.0.7
* Horde Horde Groupware Webmail Edition 4.0.4
* Horde Horde Groupware Webmail Edition 4.0.3
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Vendor Status:
Vendor had issued an update for this vulnerability
Patch Availability:
http://lists.horde.org/archives/announce/2012/000773.html
Disclosure Timeline:
Initial Release: May 09 2012
Please enable JavaScript to view the comments powered by Disqus.
blog comments powered by