CVE-2007-1473: XSS
Cross-site scripting (XSS) vulnerability in framework/NLS/NLS.php in Horde Framework before 3.1.4 RC1, when the login page contains a language selection box, allows remote attackers to inject arbitrary web script or HTML via the newlang parameter to login.php.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1473?
CVE-2007-1473 is classified as a medium severity Cross-site Scripting (XSS) vulnerability.
How do I fix CVE-2007-1473?
To mitigate CVE-2007-1473, upgrade to Horde Framework version 3.1.4 RC1 or later.
Who is affected by CVE-2007-1473?
CVE-2007-1473 affects users of Horde Framework versions before 3.1.4 RC1 that include a language selection box on the login page.
What type of attack can CVE-2007-1473 facilitate?
CVE-2007-1473 can facilitate remote attackers in injecting arbitrary web scripts or HTML through the new_lang parameter.
When was CVE-2007-1473 discovered?
CVE-2007-1473 was discovered in 2007 and has been documented since then.