CVE-2008-4182: XSS
Published Sep 23, 2008
·Updated
Cross-site scripting (XSS) vulnerability in imp/test.php in Horde Turba Contact Manager H3 2.2.1 and other versions before 2.3.1, and possibly other Horde Project products, allows remote attackers to inject arbitrary web script or HTML via the User field in an IMAP session.
Affected Software
3 affected components
Horde Turba Contact Manager H3=3.2.2
Horde Turba Contact Manager H3=2.2.1
Horde Turba Contact Manager H3=3.1.1
Event History
Sep 23, 2008
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-4182?
CVE-2008-4182 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2008-4182?
To mitigate CVE-2008-4182, upgrade to Horde Turba versions 2.3.1 or later.
3
What software is affected by CVE-2008-4182?
CVE-2008-4182 affects Horde Turba Contact Manager H3 versions 2.2.1 to 3.2.2.
4
Can CVE-2008-4182 be exploited remotely?
Yes, CVE-2008-4182 can be exploited by remote attackers to inject arbitrary web scripts.
5
What types of attacks are possible with CVE-2008-4182?
CVE-2008-4182 can lead to cross-site scripting (XSS) attacks via user input in an IMAP session.