|
|
Subscribe / Log in / New account

Cross-site scripting vulnerability in Horde/IMP 2.2.7 and 3.0

Package(s):imp horde/imp CVE #(s):
Created:May 21, 2002 Updated:June 19, 2002
Description: Version 2.2.8 of IMP has been released, it fixes some vulnerabilities. "The Horde team announces the availability of IMP 2.2.8, which prevents some potential cross-site scripting (CSS) attacks." Upgrading to IMP 3.1 or, at least, 2.2.8 is recommended (First LWN report: April 11, 2002).

Update: IMP 3.0, which was initially believed to be immune, is also vulnerable. The problem is fixed in IMP 3.1.

Alerts:
Debian DSA-126-1 imp 2002-04-16
SCO Group CSSA-2002-016.0 horde/imp 2002-04-16

to post comments

Cross-site scripting vulnerability in Horde/IMP 2.2.7 and 3.0

Posted Jun 20, 2002 17:01 UTC (Thu) by bjn (guest, #2179) [Link]

The "initially believed to be immune" part isn't accurate; we new 3.0 was vulnerable, but decided to fix it in 3.1.


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds