CVE-2005-4191: XSS
Multiple cross-site scripting (XSS) vulnerabilities in templates/tasklists/tasklists.inc in Horde Nag Task List Manager H3 before 2.0.4 allow remote authenticated users to inject arbitrary web script or HTML via (1) the tasklist's name or (2) description, when creating a new tasklist.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-4191?
CVE-2005-4191 is considered a medium severity vulnerability due to the potential for cross-site scripting attacks.
How do I fix CVE-2005-4191?
To mitigate CVE-2005-4191, upgrade to Horde Nag Task List Manager H3 version 2.0.4 or later.
What types of attacks can CVE-2005-4191 facilitate?
CVE-2005-4191 can facilitate cross-site scripting (XSS) attacks, allowing an attacker to inject malicious scripts into web pages viewed by users.
Who is affected by CVE-2005-4191?
Remote authenticated users of Horde Nag Task List Manager H3 versions prior to 2.0.4 are affected by CVE-2005-4191.
What are the affected versions of Horde Nag Task List Manager H3 for CVE-2005-4191?
The affected versions for CVE-2005-4191 include 1.1, 1.1.1, 1.1.2, 1.1.3, 2.0, 2.0.1, 2.0.2, and 2.0.3.