First published: Tue Mar 17 2009(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP before 4.2.2 and 4.3.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) smime.php, (2) pgp.php, and (3) message.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Horde IMP | =4.0 | |
Horde IMP | <=4.1.5 | |
Horde IMP | <=4.0.4 | |
Horde IMP | <=4.0.3 | |
Horde IMP | <=4.1.4 | |
Horde IMP | <=4.2.1 | |
Horde IMP | <=4.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0930 is classified as a medium severity vulnerability due to the potential for exploitation via cross-site scripting.
To fix CVE-2009-0930, upgrade to Horde IMP version 4.2.2 or later, or 4.3.3 or later.
CVE-2009-0930 can be exploited by remote attackers to inject arbitrary web scripts or HTML into specific PHP files.
CVE-2009-0930 affects Horde IMP versions prior to 4.2.2 and 4.3.3.
The impacted files in CVE-2009-0930 include smime.php, pgp.php, and message.php.