First published: Wed Jan 21 2009(Updated: )
Cross-site scripting (XSS) vulnerability in the XSS filter (framework/Text_Filter/Filter/xss.php) in Horde Application Framework 3.2.2 and 3.3, when Internet Explorer is being used, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to style attributes.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Horde application framework | =3.2.2 | |
Horde application framework | =3.3 | |
Internet Explorer |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5917 is classified as a cross-site scripting (XSS) vulnerability that can potentially allow attackers to inject malicious scripts.
To mitigate CVE-2008-5917, upgrade the Horde Application Framework to the latest version where this vulnerability is not present.
CVE-2008-5917 affects Horde Application Framework versions 3.2.2 and 3.3 when used with Internet Explorer.
CVE-2008-5917 exploits a vulnerability in the XSS filter that allows remote attackers to inject arbitrary web scripts or HTML.
A potential workaround for CVE-2008-5917 is to avoid using Internet Explorer when accessing applications using the affected versions of the Horde Application Framework.