47580Third-party advisory
http://secunia.com/advisories/47580 CVE-2012-0791
horde dynamic_imp Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Record summary
CVE-2012-0791 has a selected CVSS score of 4.3.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP before 5.0.18 and Horde Groupware Webmail Edition before 4.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) composeCache, (2) rtemode, or (3) filename_* parameters to the compose page; (4) formname parameter to the contacts popup window; or (5) IMAP mailbox names. NOTE: some of these details are obtained from third party information.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Feb 21, 2019 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
dynamic_impBrowse horde / dynamic_imp | VulnCheck | Version data not supplied | |
References
1247592Third-party advisory
http://secunia.com/advisories/47592 DSA-2485Vendor advisory
http://www.debian.org/security/2012/dsa-2485 horde.orgConfirmation
http://www.horde.org/apps/imp/docs/CHANGES horde.orgConfirmation
http://www.horde.org/apps/imp/docs/RELEASE_NOTES horde.orgConfirmation
http://www.horde.org/apps/webmail/docs/CHANGES horde.orgConfirmation
http://www.horde.org/apps/webmail/docs/RELEASE_NOTES [oss-security] 20120121 Re: Re: CVE Request -- Horde IMP -- Multiple XSS flawsmailing list
http://www.openwall.com/lists/oss-security/2012/01/22/2 51586vdb entry
http://www.securityfocus.com/bid/51586 1026553vdb entry
http://www.securitytracker.com/id?1026553 1026554vdb entry
http://www.securitytracker.com/id?1026554 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2012-0791