CVE-2005-3570: XSS
Published Nov 16, 2005
·Updated
Unspecified cross-site scripting (XSS) vulnerability in Horde before 2.2.9 allows remote attackers to inject arbitrary web script or HTML via "not properly escaped error messages".
Affected Software
9 affected components
Horde HORDE=2.2
Horde HORDE=2.2.1
Horde HORDE=2.2.3
Horde HORDE=2.2.4
Horde HORDE=2.2.4_rc1
Horde HORDE=2.2.5
Horde HORDE=2.2.6
Horde HORDE=2.2.7
Horde HORDE=2.2.8
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Nov 16, 2005
CVE Published
07:42 AM
CVE Published
via MITRE·12:37 PM
Data Sourced
via MITRE·12:37 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3570?
CVE-2005-3570 is classified as a high severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2005-3570?
To fix CVE-2005-3570, you should upgrade your Horde installation to version 2.2.9 or later.
3
What versions of Horde are affected by CVE-2005-3570?
CVE-2005-3570 affects Horde versions 2.2 through 2.2.8.
4
What type of vulnerability is CVE-2005-3570?
CVE-2005-3570 is an unspecified cross-site scripting (XSS) vulnerability.
5
Who can exploit CVE-2005-3570?
Remote attackers can exploit CVE-2005-3570 to inject arbitrary web scripts or HTML.