CVE-2004-0584: XSS
Unknown vulnerability in Horde IMP 3.2.3 and earlier, before a "security fix," does not properly validate input, which allows remote attackers to execute arbitrary script as other users via script or HTML in an e-mail message, possibly triggering a cross-site scripting (XSS) vulnerability.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0584?
CVE-2004-0584 is classified as a medium severity vulnerability, primarily allowing remote code execution due to improper input validation.
How do I fix CVE-2004-0584?
To fix CVE-2004-0584, upgrade to Horde IMP version 3.2.4 or later, which includes the necessary security fixes.
What versions of Horde IMP are affected by CVE-2004-0584?
CVE-2004-0584 affects Horde IMP versions up to and including 3.2.3, as well as earlier versions.
Can CVE-2004-0584 lead to cross-site scripting attacks?
Yes, CVE-2004-0584 can trigger a cross-site scripting (XSS) vulnerability due to unvalidated input in email messages.
Who is impacted by CVE-2004-0584?
Any users of affected versions of Horde IMP are at risk of attack through this vulnerability.