Register | Forget Password | Login
Search :
SecurityReason

News

Search

SecurityAlert

About SecurityAlert

ExploitAlert

SecurityReason Research

WLB

WLB Database

Send to WLB

About WLB

RSS

News

SecurityAlert

World Laboratory of Bugtraq

ExploitAlert

Apache

PHP

Corporate

Contact

About us

Services

SecurePHP

Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Details : SecurityAlert

  Topic : Horde 3.1.4 (RC1) fixes XSS issue
  SecurityAlert : 2427
  CVE : CVE-2007-1473
  SecurityRisk : Low  alert  (About)
  Remote Exploit : Yes
  Local Exploit : No
  Exploit Given : Yes
  Credit : Moritz Naumann
  Published : 20.03.2007

  Affected Software : Horde 3.1.4 (RC1)



  Advisory Text :  

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi,

a few hours ago, Horde Framework 3.1.4 was released. This stable release
as well as a previous development release titled 3.1.4 RC1 fix a
script/HTML injection issue which does not require pevious
authentication by the victim.

By redirecting the victims' web browser to a specially crafted URL
containing the payload this issue can be exploited. As the users'
session cookie is already set by the time the injection takes place this
issue makes the user prone to XSS attacks.

The vulnerable file is framework/NLS/NLS.php.

Example:
[Base_HREF]/horde/[Horde_App]/login.php?new_lang=%22%3E%3Cbody%20onload=
%22alert%28'XSS'%29%3B

[Horde_App] should be replaced by the name of an installed Horde
application, such as 'imp'.

This can only be exploited on installations which are configured to
display a language selection box on the login pages.

This issue was /not/ initially discovered by me. I document it here as
I happened to come across this while discovering XSS issues in Horde IMP
and to simplify fixing vulnerable versions of repackaged distributions
of this software.

The developers' release announcement can be found at:
http://lists.horde.org/archives/announce/2007/000315.html

General information on this application is available at
http://www.horde.org/

Moritz Naumann
http://moritz-naumann.com
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFF+KZ5n6GkvSd/BgwRAvSwAJ9fUFLMnQEYbT3ZftmoCBTTxYhmfACeOrQd
n4JZtVHG3wRI8CpwRbGQjaI=
=VGUL
-----END PGP SIGNATURE-----




  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

*BSD libc (strfmon) Multiple vulnerabilities

high- 2008-03-25

Maksymilian Arciemowicz discovered a Integer Overflow vulnerability in the libc library "strfmon()" function.A vulnerability could allow an attacker who successfully exploits this vulnerability to take control of the affected *BSD systems.

Apache rss

» Apache Tomcat information
   disclosure

» Apache Tomcat <=
   6.0.18 UTF8 Directory
   Traversal Vulnerability

» Apache Tomcat information
   disclosure vulnerability

» Apache Tomcat XSS
   vulnerability

PHP rss

» PHP 5.2.6 (error_log)
   safe_mode bypass

» PHP 5.2.6 chdir(),ftok()
   (standard ext) safe_mode
   bypass

» PHP 5.2.6 posix_access()
   (posix ext) safe_mode
   bypass

» PHP 5.2.5 and prior :
   *printf() functions
   Integer Overflow

Copyright © SecurityReason. All Rights Reserved.