Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 77872 - www-apps/horde 3.0 XSS issues
Summary: www-apps/horde 3.0 XSS issues
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High trivial (vote)
Assignee: Gentoo Security
URL: http://www.securityfocus.com/archive/...
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2005-01-13 11:25 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2005-01-16 05:13 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-01-13 11:25:45 UTC
---
Horde contains two XSS attacks that can be exploited through GET requests.  
Once exploited, these requests could be used to execute any javascript
commands in the context of that user, potentially including but not limited
to reading and deleting email, and stealing auth tokens. 
---

Full details on the BugTraq Announcement
Comment 1 Thierry Carrez (RETIRED) gentoo-dev 2005-01-13 11:37:33 UTC
Fixed in 3.0.1 (3.0.2 is already out).
vapier/web-apps: please bump the ~ version to 3.0.2
No stable marking needed, no GLSA (as this is ~).
Comment 2 SpanKY gentoo-dev 2005-01-16 03:03:52 UTC
now in portage
Comment 3 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-01-16 05:13:23 UTC
Thx spanKY