CVE-2012-0791

EXPLOITED

Horde IMP <5.0.18, Horde Groupware Webmail Edition <4.0.6 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP before 5.0.18 and Horde Groupware Webmail Edition before 4.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) composeCache, (2) rtemode, or (3) filename_* parameters to the compose page; (4) formname parameter to the contacts popup window; or (5) IMAP mailbox names. NOTE: some of these details are obtained from third party information.

Scores

EPSS 0.0062
EPSS Percentile 69.7%

Exploitation Intel

VulnCheck KEV 2019-02-21

Classification

CWE
CWE-79
Status published

Affected Products (50)

horde/dynamic_imp < 5.0.17
horde/dynamic_imp
horde/dynamic_imp
horde/dynamic_imp
horde/dynamic_imp
horde/dynamic_imp
horde/dynamic_imp
horde/dynamic_imp
horde/dynamic_imp
horde/dynamic_imp
horde/dynamic_imp
horde/dynamic_imp
horde/dynamic_imp
horde/dynamic_imp
horde/dynamic_imp
... and 35 more

Timeline

Published Jan 24, 2012
Tracked Since Feb 18, 2026