CVE-2010-3695: XSS
Cross-site scripting (XSS) vulnerability in fetchmailprefs.php in Horde IMP before 4.3.8, and Horde Groupware Webmail Edition before 1.2.7, allows remote attackers to inject arbitrary web script or HTML via the fmid parameter in a fetchmailprefssave action, related to the Fetchmail configuration.
Other sources
Upstream has released a new version of IMP (4.3.8) [1] that corrects the following flaw [2],[3]:
Fixed an XSS vulnerability in the Fetchmail configuration.
This has been assigned the name CVE-2010-3695. The current version of IMP in Fedora is 4.3.7 and is vulnerable to this flaw.
[1] http://lists.horde.org/archives/announce/2010/000557.html [2] http://git.horde.org/diff.php/imp/fetchmailprefs.php?rt=horde&r1=1.39.4.10&r2=1.39.4.11 [3] http://archives.neohapsis.com/archives/fulldisclosure/2010-09/0379.html
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3695?
CVE-2010-3695 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2010-3695?
To fix CVE-2010-3695, upgrade to Horde IMP version 4.3.8 or later, or Horde Groupware Webmail Edition version 1.2.7 or later.
Who is affected by CVE-2010-3695?
CVE-2010-3695 affects multiple versions of Horde IMP prior to 4.3.8 and Horde Groupware Webmail Edition prior to 1.2.7.
What types of attacks can exploit CVE-2010-3695?
CVE-2010-3695 can be exploited by attackers to inject arbitrary web scripts or HTML through the fm_id parameter.
When was CVE-2010-3695 disclosed?
CVE-2010-3695 was disclosed in September 2010.