_______________________________________________________________________
Package : egroupware
Date : August 9, 2009
Affected: Corporate 3.0
_______________________________________________________________________
Problem Description:
A vulnerability has been found and corrected in egroupware:
The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php
in KSES, as used in eGroupWare before 1.4.003, Moodle before 1.8.5,
and other products, allows remote attackers to bypass HTML filtering
and conduct cross-site scripting (XSS) attacks via a string containing
crafted URL protocols (CVE-2008-1502).
This update fixes this vulnerability.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cg ... -2008-1502
_______________________________________________________________________