CVE-2006-4255: XSS
Cross-site scripting (XSS) vulnerability in horde/imp/search.php in Horde IMP H3 before 4.1.3 allows remote attackers to include arbitrary web script or HTML via multiple unspecified vectors related to folder names, as injected into the vfolderlabel form field in the IMP search screen.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4255?
CVE-2006-4255 is considered a moderate severity vulnerability due to the potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2006-4255?
To fix CVE-2006-4255, you should upgrade Horde IMP to version 4.1.3 or later.
Which versions of Horde IMP are affected by CVE-2006-4255?
CVE-2006-4255 affects Horde IMP versions before 4.1.3, including versions 2.0 through 4.0.
What type of vulnerability is CVE-2006-4255?
CVE-2006-4255 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML.
What component of Horde is impacted by CVE-2006-4255?
CVE-2006-4255 specifically impacts the search.php component in Horde IMP.