First published: Wed Aug 13 2008(Updated: )
Multiple unspecified vulnerabilities in Horde Groupware Webmail before Edition 1.1.1 (final) have unknown impact and attack vectors related to "unescaped output," possibly cross-site scripting (XSS), in the (1) object browser and (2) contact view.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Horde Groupware | =1.0.1 | |
Horde Groupware | =1.1 | |
Horde Groupware | =1.0.5 | |
Horde Groupware | =1.0.7 | |
Horde Groupware | =1.0.3 | |
Horde Groupware | =1.0 | |
Horde Groupware | =1.0.2 | |
Horde Groupware | =1.0.6 | |
Horde Groupware | =1.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3650 is categorized with an unspecified severity, highlighting potential risks associated with multiple vulnerabilities.
To resolve CVE-2008-3650, upgrade to Horde Groupware Webmail Edition version 1.1.1 or later.
CVE-2008-3650 includes vulnerabilities related to unescaped output, which may lead to cross-site scripting (XSS) attacks.
CVE-2008-3650 affects Horde Groupware Webmail versions up to and including 1.1.
CVE-2008-3650 impacts the object browser and contact view components of Horde Groupware Webmail.