CVE-2009-2360: XSS
Published Jul 8, 2009
·Updated
Cross-site scripting (XSS) vulnerability in passwd/main.php in the Passwd module before 3.1.1 for Horde allows remote attackers to inject arbitrary web script or HTML via the backend parameter.
Affected Software
6 affected components
Horde Passwd=2.1
Horde Passwd=2.2
Horde Passwd=2.0
Horde Passwd<=3.1
Horde Passwd=2.2.2
Horde Passwd=2.2.1
Remediation
Patch Available
Patch Available
Patch Available
Event History
Jul 8, 2009
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2360?
CVE-2009-2360 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2009-2360?
To fix CVE-2009-2360, you should upgrade to Horde Passwd version 3.1.1 or later.
3
What systems are affected by CVE-2009-2360?
CVE-2009-2360 affects Horde Passwd versions prior to 3.1.1, including versions 2.0 to 2.2.2.
4
What type of vulnerability is CVE-2009-2360?
CVE-2009-2360 is a cross-site scripting (XSS) vulnerability that allows for the injection of malicious scripts.
5
Who can exploit CVE-2009-2360?
Remote attackers can exploit CVE-2009-2360 to inject arbitrary web scripts or HTML through the backend parameter.