CVE-2005-4080: XSS
Horde IMP 4.0.4 and earlier does not sanitize strings containing UTF16 null characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via UTF16 encoded attachments and strings that will be executed when viewed using Internet Explorer, which ignores the characters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-4080?
CVE-2005-4080 is classified as a severity level that enables potential cross-site scripting (XSS) attacks.
How do I fix CVE-2005-4080?
To fix CVE-2005-4080, it is recommended to update Horde IMP to the latest version that sanitizes input properly.
What versions are affected by CVE-2005-4080?
CVE-2005-4080 affects multiple versions of Horde IMP including 4.0.4, 4.0, 3.2.5, 3.2.4, and several others.
Can CVE-2005-4080 be exploited remotely?
Yes, CVE-2005-4080 can be exploited remotely when a user views an infected UTF16 string or attachment.
What is the main issue with CVE-2005-4080?
The main issue with CVE-2005-4080 is the failure to sanitize UTF16 null characters, allowing for XSS attacks in Internet Explorer.