Get a Pentest and security assessment of your IT network.

Advisories

Open Source CERT Security Advisory 2008.12

Two cross-site scripting (XSS) vulnerabilities were reported in Horde Framework. The first of which is that the Horde framework fails to properly sanitize the filename of MIME attachments on received emails. The second vulnerability has a wider impact. Horde relies on code similar to Popoon’s externalinput.php to filter out potential XSS attacks on user-supplied input. This filter, and the original, fail to fully sanitize user data.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/69852/oCERT-2008-012.txt

Source: https://packetstormsecurity.com/files/69852/Open-Source-CERT-Security-Advisory-2008.12.html

Related posts
Advisories

CSIS2005-1.txt

Advisories

Secunia Security Advisory 17625

Advisories

Secunia Security Advisory 20411

Advisories

Secunia Security Advisory 23300