First published: Sat Jul 21 2001(Updated: )
Cross-site scripting vulnerability in Horde Internet Messaging Program (IMP) before 2.2.6 and 1.2.6 allows remote attackers to execute arbitrary Javascript embedded in an email.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Horde | =2.2.5 | |
Horde | =2.2.1 | |
Horde | =2.2.2 | |
Horde | =2.2.4 | |
Horde | =2.0 | |
Horde | =2.2 | |
Horde | =2.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1257 is considered a high severity cross-site scripting vulnerability allowing execution of arbitrary JavaScript.
CVE-2001-1257 allows remote attackers to execute malicious JavaScript on the client side, potentially compromising user data.
To fix CVE-2001-1257, upgrade to Horde IMP version 2.2.6 or 1.2.6 or later.
CVE-2001-1257 affects Horde IMP versions prior to 2.2.6 and 1.2.6, including 2.2.5 and 2.2.1.
CVE-2001-1257 enables cross-site scripting attacks through email, allowing execution of embedded JavaScript.