First published: Tue Sep 23 2008(Updated: )
Cross-site scripting (XSS) vulnerability in imp/test.php in Horde Turba Contact Manager H3 2.2.1 and other versions before 2.3.1, and possibly other Horde Project products, allows remote attackers to inject arbitrary web script or HTML via the User field in an IMAP session.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Horde Turba Contact Manager | =3.2.2 | |
Horde Turba Contact Manager | =2.2.1 | |
Horde Turba Contact Manager | =3.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4182 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
To mitigate CVE-2008-4182, upgrade to Horde Turba versions 2.3.1 or later.
CVE-2008-4182 affects Horde Turba Contact Manager H3 versions 2.2.1 to 3.2.2.
Yes, CVE-2008-4182 can be exploited by remote attackers to inject arbitrary web scripts.
CVE-2008-4182 can lead to cross-site scripting (XSS) attacks via user input in an IMAP session.