CVE-2010-3693: XSS
Cross-site scripting (XSS) vulnerability in Horde Dynamic IMP (DIMP) before 1.1.5, and Horde Groupware Webmail Edition before 1.2.7, allows remote attackers to inject arbitrary web script or HTML via vectors related to displaying mailbox names.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3693?
CVE-2010-3693 has a medium severity level due to its potential for cross-site scripting attacks.
How do I fix CVE-2010-3693?
To fix CVE-2010-3693, upgrade Horde Dynamic IMP to version 1.1.5 or later and Horde Groupware Webmail Edition to version 1.2.7 or later.
What systems are affected by CVE-2010-3693?
CVE-2010-3693 affects Horde Dynamic IMP versions prior to 1.1.5 and Horde Groupware Webmail Edition versions prior to 1.2.7.
What kind of attack can exploit CVE-2010-3693?
CVE-2010-3693 can be exploited through cross-site scripting (XSS), allowing attackers to inject malicious scripts into web pages.
How can I determine if my system is vulnerable to CVE-2010-3693?
You can determine vulnerability to CVE-2010-3693 by checking the version of your installed Horde Dynamic IMP and Horde Groupware Webmail Edition against the affected versions.