CVE-2016-2228

Cross-site scripting (XSS) vulnerability in horde/templates/topbar/_menubar.html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to inject arbitrary web script or HTML via the searchfield parameter, as demonstrated by a request to xplorer/gollem/manager.php.
Configurations

Configuration 1 (hide)

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:horde:groupware:*:*:*:*:*:*:*:*
cpe:2.3:a:horde:horde_groupware:*:*:*:*:webmail_edition:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*

History

21 Nov 2024, 02:48

Type Values Removed Values Added
References () http://bugs.horde.org/ticket/14213 - () http://bugs.horde.org/ticket/14213 -
References () http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177484.html - () http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177484.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177584.html - () http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177584.html -
References () http://lists.horde.org/archives/announce/2016/001148.html - Vendor Advisory () http://lists.horde.org/archives/announce/2016/001148.html - Vendor Advisory
References () http://lists.horde.org/archives/announce/2016/001149.html - Vendor Advisory () http://lists.horde.org/archives/announce/2016/001149.html - Vendor Advisory
References () http://www.debian.org/security/2016/dsa-3497 - () http://www.debian.org/security/2016/dsa-3497 -
References () http://www.openwall.com/lists/oss-security/2016/02/06/4 - () http://www.openwall.com/lists/oss-security/2016/02/06/4 -
References () http://www.openwall.com/lists/oss-security/2016/02/06/5 - () http://www.openwall.com/lists/oss-security/2016/02/06/5 -
References () https://github.com/horde/horde/blob/e838d4c800b0d1ecaf8b4cc613fd3af4f994c79c/bundles/webmail/docs/CHANGES - () https://github.com/horde/horde/blob/e838d4c800b0d1ecaf8b4cc613fd3af4f994c79c/bundles/webmail/docs/CHANGES -
References () https://github.com/horde/horde/commit/ab07a1b447de34e13983b4d7ceb18b58c3a358d8 - Exploit () https://github.com/horde/horde/commit/ab07a1b447de34e13983b4d7ceb18b58c3a358d8 - Exploit

Information

Published : 2016-04-13 16:59

Updated : 2024-11-21 02:48


NVD link : CVE-2016-2228

Mitre link : CVE-2016-2228

CVE.ORG link : CVE-2016-2228


JSON object : View

Products Affected

debian

  • debian_linux

fedoraproject

  • fedora

horde

  • groupware
  • horde_groupware
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')