First published: Wed Dec 14 2005(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Horde Turba H3 2.0.4 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the address book and (2) contact data.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Horde Turba Contact Manager H3 | <=2.0.4 | |
Horde Turba Contact Manager H3 | =2.0 | |
Horde Turba Contact Manager H3 | =2.0.1 | |
Horde Turba Contact Manager H3 | =2.0.2 | |
Horde Turba Contact Manager H3 | =2.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4242 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2005-4242, upgrade to Horde Turba H3 version 2.0.5 or later, which addresses these vulnerabilities.
CVE-2005-4242 allows remote attackers to exploit multiple cross-site scripting vulnerabilities via the address book and contact data.
Versions of Horde Turba H3 affected by CVE-2005-4242 include 2.0.4 and earlier, including 2.0.3, 2.0.2, and 2.0.1.
The impact of CVE-2005-4242 on web applications includes the risk of attackers injecting arbitrary web scripts or HTML, which can lead to data theft or session hijacking.