First published: Tue Dec 13 2005(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in templates/tasklists/tasklists.inc in Horde Nag Task List Manager H3 before 2.0.4 allow remote authenticated users to inject arbitrary web script or HTML via (1) the tasklist's name or (2) description, when creating a new tasklist.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Horde Nag Task List Manager H3 | =1.1.2 | |
Horde Nag Task List Manager H3 | =2.0.2 | |
Horde Nag Task List Manager H3 | =2.0 | |
Horde Nag Task List Manager H3 | =2.0.1 | |
Horde Nag Task List Manager H3 | =1.1 | |
Horde Nag Task List Manager H3 | =1.1.1 | |
Horde Nag Task List Manager H3 | =2.0.3 | |
Horde Nag Task List Manager H3 | =1.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4191 is considered a medium severity vulnerability due to the potential for cross-site scripting attacks.
To mitigate CVE-2005-4191, upgrade to Horde Nag Task List Manager H3 version 2.0.4 or later.
CVE-2005-4191 can facilitate cross-site scripting (XSS) attacks, allowing an attacker to inject malicious scripts into web pages viewed by users.
Remote authenticated users of Horde Nag Task List Manager H3 versions prior to 2.0.4 are affected by CVE-2005-4191.
The affected versions for CVE-2005-4191 include 1.1, 1.1.1, 1.1.2, 1.1.3, 2.0, 2.0.1, 2.0.2, and 2.0.3.