CVE-2009-0930: XSS
Published Mar 17, 2009
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP before 4.2.2 and 4.3.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) smime.php, (2) pgp.php, and (3) message.php.
Affected Software
7 affected components
Debian Horde Imp<=4.0.2
Debian Horde Imp<=4.0.3
Debian Horde Imp<=4.0.4
Debian Horde Imp<=4.1.4
Debian Horde Imp<=4.1.5
Debian Horde Imp<=4.2.1
Debian Horde Imp=4.0
Event History
Mar 17, 2009
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-0930?
CVE-2009-0930 is classified as a medium severity vulnerability due to the potential for exploitation via cross-site scripting.
2
How do I fix CVE-2009-0930?
To fix CVE-2009-0930, upgrade to Horde IMP version 4.2.2 or later, or 4.3.3 or later.
3
What kind of attacks can exploit CVE-2009-0930?
CVE-2009-0930 can be exploited by remote attackers to inject arbitrary web scripts or HTML into specific PHP files.
4
Which versions of Horde IMP are affected by CVE-2009-0930?
CVE-2009-0930 affects Horde IMP versions prior to 4.2.2 and 4.3.3.
5
What are the impacted files in CVE-2009-0930?
The impacted files in CVE-2009-0930 include smime.php, pgp.php, and message.php.