CVE-2008-4182

Horde Turba Contact Manager H3 - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in imp/test.php in Horde Turba Contact Manager H3 2.2.1 and other versions before 2.3.1, and possibly other Horde Project products, allows remote attackers to inject arbitrary web script or HTML via the User field in an IMAP session.

Scores

EPSS 0.0044
EPSS Percentile 62.9%

Classification

CWE
CWE-79
Status published

Affected Products (4)

horde/turba_contact_manager_h3
horde/turba_contact_manager_h3
horde/turba_contact_manager_h3
n/a/n/a

Timeline

Published Sep 23, 2008
Tracked Since Feb 18, 2026