CVE-2005-3759: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Horde before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) gzip/tar and (2) css MIME viewers, which do not filter or escape dangerous HTML when extracting and displaying attachments.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3759?
CVE-2005-3759 has been classified as a moderate severity vulnerability due to the potential for arbitrary web script injection.
How do I fix CVE-2005-3759?
To fix CVE-2005-3759, upgrade to Horde version 3.0.7 or later, which includes patches to address these vulnerabilities.
What types of attacks are possible due to CVE-2005-3759?
CVE-2005-3759 allows remote attackers to execute arbitrary HTML and web scripts, potentially leading to session hijacking or data manipulation.
Which versions of Horde are affected by CVE-2005-3759?
CVE-2005-3759 affects Horde versions prior to 3.0.7, specifically versions 1.2.x, 2.2.x, and 3.0.x.
How can I check if my system is vulnerable to CVE-2005-3759?
You can determine if your system is vulnerable to CVE-2005-3759 by checking the installed version of Horde and comparing it against the fixed version 3.0.7 or later.