<?xml version="1.0" encoding="ISO-8859-1"?>
<?xml-stylesheet href="http://bugs.horde.org/themes/feed-rss.xsl" type="text/xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
 <channel>
  <title>The parameter 'object[name]' is not sanitized in the page '/horde/turba/add.php'</title>
  <pubDate>Sat, 22 Nov 2008 09:54:25 -0500</pubDate>
  <link>http://bugs.horde.org/ticket/6906</link>
  <atom:link rel="self" type="application/rss+xml" title="The parameter 'object[name]' is not sanitized in the page '/horde/turba/add.php'" href="http://bugs.horde.org/ticket/6906/rss" />
  <description>The parameter 'object[name]' is not sanitized in the page '/horde/turba/add.php'</description>

  
  
  <item>
   <title>Hello,

I found a security hole in Turba H3 2.1.7
This is</title>
   <description>Hello,

I found a security hole in Turba H3 2.1.7
This is a Cross Site Scripting (XSS) vulnerability.
The parameter 'object[name]' is not sanitized in the page '/horde/turba/add.php'

POC:

&lt;input type=&quot;text&quot; name=&quot;object[name]&quot; id=&quot;object[name]&quot; size=&quot;40&quot; value=&quot;&lt;script&gt;alert('XSS by Nicolas Kerschenbaum');&lt;/script&gt;&quot;  maxlength=&quot;255&quot; /&gt;



Could you tell me if this vulnerability is corrected in the last version of turba (2.2).

Regards

Nicolas Kerschenbaum</description>
   <pubDate>Thu, 12 Jun 2008 12:28:54 -0400</pubDate>
   <link>http://bugs.horde.org/ticket/6906#t46330</link>
  </item>
  <item>
   <title>Yes, it is.</title>
   <description>Yes, it is.</description>
   <pubDate>Thu, 12 Jun 2008 13:01:50 -0400</pubDate>
   <link>http://bugs.horde.org/ticket/6906#t46333</link>
  </item>
  <item>
   <title>Well, there was another problem, but not in add.php itself -</title>
   <description>Well, there was another problem, but not in add.php itself - are you saying the vulnerability you see is on the add form itself?</description>
   <pubDate>Thu, 12 Jun 2008 14:24:58 -0400</pubDate>
   <link>http://bugs.horde.org/ticket/6906#t46336</link>
  </item>
  <item>
   <title>1) I add a contact (page: '/horde/turba/add.php') with the n</title>
   <description>1) I add a contact (page: '/horde/turba/add.php') with the name :   Jean Dupont&lt;script&gt;alert('XMCO');&lt;/script&gt;
http://img258.imageshack.us/img258/3708/formao0.png

2) I see my contact list (page: '/horde/services/obrowser/?path=turba/localsql:heremylogin')
and there is a XSS
http://img246.imageshack.us/img246/5604/xsswt6.png

So, if this security bug is fixed, which version is not vulnerable ?

Regards</description>
   <pubDate>Fri, 13 Jun 2008 04:59:58 -0400</pubDate>
   <link>http://bugs.horde.org/ticket/6906#t46389</link>
  </item>
  <item>
   <title>your initial report was misleading about where the vulnerabi</title>
   <description>your initial report was misleading about where the vulnerability is (xss is a display problem, so add.php isn't the issue). we are currently investigating.</description>
   <pubDate>Fri, 13 Jun 2008 10:58:12 -0400</pubDate>
   <link>http://bugs.horde.org/ticket/6906#t46408</link>
  </item>
  <item>
   <title>Indeed, the page add.php is not the issue, but the parameter</title>
   <description>Indeed, the page add.php is not the issue, but the parameter 'object[name]', saved in add.php page, is not sanitized in the page '/horde/services/obrowser/?path=turba/localsql'.

</description>
   <pubDate>Fri, 13 Jun 2008 11:43:38 -0400</pubDate>
   <link>http://bugs.horde.org/ticket/6906#t46414</link>
  </item>
  <item>
   <title>that's not even part of turba</title>
   <description>that's not even part of turba</description>
   <pubDate>Fri, 13 Jun 2008 11:52:26 -0400</pubDate>
   <link>http://bugs.horde.org/ticket/6906#t46415</link>
  </item>
  <item>
   <title>So could you remove this ticket, I will post a new one in th</title>
   <description>So could you remove this ticket, I will post a new one in the Horde Bugs topic.

Regards
</description>
   <pubDate>Fri, 13 Jun 2008 11:57:39 -0400</pubDate>
   <link>http://bugs.horde.org/ticket/6906#t46416</link>
  </item>
  <item>
   <title>no, i already moved it to the horde queue</title>
   <description>no, i already moved it to the horde queue</description>
   <pubDate>Fri, 13 Jun 2008 12:12:11 -0400</pubDate>
   <link>http://bugs.horde.org/ticket/6906#t46428</link>
  </item>
  <item>
   <title>Changes have been made in CVS for this ticket:

http://cvs.h</title>
   <description>Changes have been made in CVS for this ticket:

http://cvs.horde.org/diff.php/horde/docs/CHANGES?r1=1.1108&amp;r2=1.1109&amp;ty=u
http://cvs.horde.org/diff.php/horde/services/obrowser/index.php?r1=1.18&amp;r2=1.19&amp;ty=u</description>
   <pubDate>Fri, 13 Jun 2008 17:43:31 -0400</pubDate>
   <link>http://bugs.horde.org/ticket/6906#t46443</link>
  </item>
  <item>
   <title>This is fixed in CVS, and Horde 3.2.1 will be out with the f</title>
   <description>This is fixed in CVS, and Horde 3.2.1 will be out with the fix presently.</description>
   <pubDate>Fri, 13 Jun 2008 17:46:20 -0400</pubDate>
   <link>http://bugs.horde.org/ticket/6906#t46444</link>
  </item>
  

 </channel>
</rss>
