RSS   Vulnerabilities for 'Dynamic imp'   RSS

2012-01-24
 
CVE-2012-0791

CWE-79
 

 
Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP before 5.0.18 and Horde Groupware Webmail Edition before 4.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) composeCache, (2) rtemode, or (3) filename_* parameters to the compose page; (4) formname parameter to the contacts popup window; or (5) IMAP mailbox names. NOTE: some of these details are obtained from third party information.

 
2011-04-04
 
CVE-2010-3693

CWE-79
 

 
Cross-site scripting (XSS) vulnerability in Horde Dynamic IMP (DIMP) before 1.1.5, and Horde Groupware Webmail Edition before 1.2.7, allows remote attackers to inject arbitrary web script or HTML via vectors related to displaying mailbox names.

 

 >>> Vendor: Horde 32 Products
Horde
IMP
Application framework
Passwd
Kronolith
Turba
Accounts
Chora
Forwards
Mnemo
Vaction
NAG
Kronolith h3
Horde application framework
Nag task list manager h3
Turba h3
Ingo h3
Groupware
Framework
Groupware webmail edition
Turba contact manager
Turba contact manager h3
Mnemo h3
Nag h3
Horde groupware
Gollem
Dynamic imp
Kronolith h4
Internet mail program
Horde image api
Horde image
Horde imp


Copyright 2019, cxsecurity.com

 

Back to Top