Affected Versions:
Horde IMP 4.3.7 vulnerability description:
Bugtraq id: 43515
IMP is a powerful Web-based email program developed by the Horde project team and can be used in Linux/Unix or Windows operating systems.
IMP Webmail does not properly filter the fm_id URL parameters submitted to the fetchmailprefs. php script. Remote attackers can execute stored cross-site scripting attacks by submitting malicious URL requests. The injected code is executed when the user accesses the mail to obtain the preference page.
<* Reference
Http://marc.info /? L = bugtraq & m = 128560937505716 & w = 2
Http://secunia.com/advisories/41627/
*>
Test method:
[Path_to_horde_imp]/fetchmailprefs. php? ActionID = fetchmail_prefs_save & fm_driver = imap & fm_id = zzz % 22% 3E % 3 Cscript % 3 Ealert % 28% 27XSS % 27% 29% 3C % 2 Fscript % 3E % 3Cx + y % 3D % 22 & fm_protocol = pop3 & fm_lmailbox = INBOX & save = Create
Vendor patch:
Horde
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://git.horde.org/diff.php/imp/fetchmailprefs.php? Rt = horde & r1 = 1.39.4.10 & r2 = 1.39.4.11