CVE-2005-1313: XSS
Published Apr 27, 2005
·Updated
Cross-site scripting (XSS) vulnerability in Horde Passwd module before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
Affected Software
4 affected components
Horde Passwd=2.1
Horde Passwd=2.2
Horde Passwd=2.0
Horde Passwd=2.2.1
Remediation
Patch Available
Event History
Apr 27, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1313?
CVE-2005-1313 is classified as a moderate-severity cross-site scripting vulnerability.
2
How do I fix CVE-2005-1313?
To fix CVE-2005-1313, you should update the Horde Passwd module to version 2.2.2 or later.
3
What versions of Horde Passwd are affected by CVE-2005-1313?
CVE-2005-1313 affects Horde Passwd versions 2.0, 2.1, 2.2, and 2.2.1.
4
Can CVE-2005-1313 be exploited remotely?
Yes, CVE-2005-1313 allows remote attackers to inject scripts or HTML via the parent's frame page title.
5
Is user interaction required to exploit CVE-2005-1313?
No, CVE-2005-1313 can be exploited without requiring user interaction.