CVE-2005-4190: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Horde Application Framework before 3.0.8 allow remote authenticated users to inject arbitrary web script or HTML via multiple vectors, as demonstrated by (1) the identity field, (2) Category and (3) Label search fields, (4) the Mobile Phone field, and (5) Date and (6) Time fields when importing CSV files, as exploited through modules such as (a) Turba Address Book, (b) Kronolith, (c) Mnemo, and (d) Nag.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What are the vulnerabilities associated with CVE-2005-4190?
CVE-2005-4190 describes multiple cross-site scripting (XSS) vulnerabilities that allow remote authenticated users to inject arbitrary web script or HTML into various fields.
What versions of Horde Application Framework are affected by CVE-2005-4190?
CVE-2005-4190 affects multiple versions of the Horde Application Framework, including versions prior to 3.0.8.
How can I mitigate the risks posed by CVE-2005-4190?
To mitigate the risks associated with CVE-2005-4190, users should upgrade to Horde Application Framework version 3.0.8 or later.
What symptoms indicate a potential exploitation of CVE-2005-4190?
Symptoms of exploitation may include unexpected HTML content or scripts being executed in the browser when interacting with certain fields of the application.
Who is primarily affected by CVE-2005-4190?
CVE-2005-4190 primarily affects organizations using vulnerable versions of the Horde Application Framework, especially those with authenticated user interactions.