CVE-2009-0931: XSS
Published Mar 17, 2009
·Updated
Cross-site scripting (XSS) vulnerability in the tag cloud search script (horde/services/portal/cloudsearch.php) in Horde before 3.2.4 and 3.3.3, and Horde Groupware before 1.1.5, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
9 affected components
Debian Horde<=3.3.1
Debian Horde Groupware<=1.1.2
Debian Horde=3.2.2
Debian Horde Groupware<=1.1.4
Debian Horde Groupware<=1.1.3
Debian Horde=3.2.3
Debian Horde=3.3
Debian Horde Groupware<=1.1.1
Debian Horde<=3.3.2
Remediation
Patch Available
Event History
Mar 17, 2009
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-0931?
CVE-2009-0931 has a moderate severity level due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2009-0931?
To mitigate CVE-2009-0931, upgrade to Horde version 3.2.4 or later, or Horde Groupware version 1.1.5 or later.
3
What software is affected by CVE-2009-0931?
CVE-2009-0931 affects various versions of Horde and Horde Groupware prior to specified versions.
4
Can CVE-2009-0931 allow attackers to execute scripts?
Yes, CVE-2009-0931 allows remote attackers to inject arbitrary web scripts or HTML.
5
Is there a security patch available for CVE-2009-0931?
Yes, security patches are available in the updated versions of both Horde and Horde Groupware.