CVE-2005-1321: XSS
Published Apr 27, 2005
·Updated
Cross-site scripting (XSS) vulnerability in Horde Vacation module before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
Affected Software
4 affected components
Horde Vaction=1.0a
Horde Vaction=2.1
Horde Vaction=2.2
Horde Vaction=2.2.1
Remediation
Patch Available
Event History
Apr 27, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1321?
CVE-2005-1321 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2005-1321?
To fix CVE-2005-1321, upgrade to Horde Vacation module version 2.2.2 or later.
3
What types of attacks can exploit CVE-2005-1321?
CVE-2005-1321 can be exploited to inject arbitrary web scripts or HTML into users' browsers.
4
Which versions of Horde Vacation are affected by CVE-2005-1321?
CVE-2005-1321 affects Horde Vacation versions 1.0a, 2.2.1, 2.2, and 2.1.
5
Is there a way to mitigate CVE-2005-1321 if I cannot upgrade?
If you cannot upgrade, consider implementing input validation and output encoding to mitigate the risk of CVE-2005-1321.