CVE-2012-0791
EXPLOITEDHorde IMP <5.0.18, Horde Groupware Webmail Edition <4.0.6 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP before 5.0.18 and Horde Groupware Webmail Edition before 4.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) composeCache, (2) rtemode, or (3) filename_* parameters to the compose page; (4) formname parameter to the contacts popup window; or (5) IMAP mailbox names. NOTE: some of these details are obtained from third party information.
References (11)
Scores
EPSS
0.0062
EPSS Percentile
69.7%
Exploitation Intel
VulnCheck KEV
2019-02-21
Classification
CWE
CWE-79
Status
published
Affected Products (50)
horde/dynamic_imp
< 5.0.17
horde/dynamic_imp
horde/dynamic_imp
horde/dynamic_imp
horde/dynamic_imp
horde/dynamic_imp
horde/dynamic_imp
horde/dynamic_imp
horde/dynamic_imp
horde/dynamic_imp
horde/dynamic_imp
horde/dynamic_imp
horde/dynamic_imp
horde/dynamic_imp
horde/dynamic_imp
... and 35 more
Timeline
Published
Jan 24, 2012
Tracked Since
Feb 18, 2026