CVE-2005-4192: XSS
Multiple cross-site scripting (XSS) vulnerabilities in templates/notepads/notepads.inc in Horde Mnemo Note Manager H3 before 2.0.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) the notepad's name or (2) description, when creating a new notepad.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-4192?
CVE-2005-4192 has a moderate severity level, as it allows authenticated users to exploit XSS vulnerabilities.
How do I fix CVE-2005-4192?
To fix CVE-2005-4192, upgrade to Horde Mnemo Note Manager H3 version 2.0.3 or later.
Who is affected by CVE-2005-4192?
Users of Horde Mnemo Note Manager H3 versions prior to 2.0.3 are affected by CVE-2005-4192.
What types of attacks can be performed with CVE-2005-4192?
CVE-2005-4192 allows attackers to inject arbitrary web scripts or HTML through notepad names or descriptions.
Is CVE-2005-4192 specific to certain versions of Horde Mnemo Note Manager?
Yes, CVE-2005-4192 specifically affects versions 2.0.1, 2.0.2, and 2.0 of Horde Mnemo Note Manager H3.