LWN.net Logo

horde3: cross-site scripting

Package(s):horde3 CVE #(s):CVE-2012-0909
Created:February 20, 2012 Updated:February 22, 2012
Description: From the CVE entry:

Cross-site scripting (XSS) vulnerability in Horde_Form in Horde Groupware Webmail Edition before 4.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to email verification. NOTE: Some of these details are obtained from third party information.

Alerts:
openSUSE openSUSE-SU-2012:0286-1 2012-02-20
Mageia MGASA-2012-0239 2012-08-26

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds