LWN.net Logo

imp4: cross-site scripting

Package(s):imp4 CVE #(s):CVE-2010-3695
Created:March 28, 2011 Updated:March 30, 2011
Description: From the Debian advisory:

Moritz Naumann discovered that imp4, a webmail component for the horde framework, is prone to cross-site scripting attacks by a lack of input sanitizing of certain fetchmail information.

Alerts:
Debian DSA-2204-1 2011-03-27
Mageia MGASA-2012-0239 2012-08-26

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds