LWN.net Logo

horde3-dimp: cross-site scripting

Package(s):horde3-dimp CVE #(s):CVE-2012-0791
Created:February 20, 2012 Updated:June 4, 2012
Description: From the CVE entry:

Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP before 5.0.18 and Horde Groupware Webmail Edition before 4.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) composeCache, (2) rtemode, or (3) filename_* parameters to the compose page; (4) formname parameter to the contacts popup window; or (5) IMAP mailbox names. NOTE: some of these details are obtained from third party information.

Alerts:
openSUSE openSUSE-SU-2012:0287-1 2012-02-20
Debian DSA-2485-1 2012-06-03
Mageia MGASA-2012-0239 2012-08-26

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds