CVE Database
/

CVE-2005-4190

Back to search

CVE-2005-4190

Published: Dec 13, 2005

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in Horde Application Framework before 3.0.8 allow remote authenticated users to inject arbitrary web script or HTML via multiple vectors, as demonstrated by (1) the identity field, (2) Category and (3) Label search fields, (4) the Mobile Phone field, and (5) Date and (6) Time fields when importing CSV files, as exploited through modules such as (a) Turba Address Book, (b) Kronolith, (c) Mnemo, and (d) Nag.

VendorProductVersions

n/a

n/a

affected
n/a

References

15810
vdb-entry
x_refsource_BID
15806
vdb-entry
x_refsource_BID
15808
vdb-entry
x_refsource_BID
ADV-2005-2835
vdb-entry
x_refsource_VUPEN
15804
vdb-entry
x_refsource_BID
15803
vdb-entry
x_refsource_BID
19619
third-party-advisory
x_refsource_SECUNIA
DSA-1033
vendor-advisory
x_refsource_DEBIAN
SUSE-SR:2006:016
vendor-advisory
x_refsource_SUSE
15802
vdb-entry
x_refsource_BID
17970
third-party-advisory
x_refsource_SECUNIA
20960
third-party-advisory
x_refsource_SECUNIA
19897
third-party-advisory
x_refsource_SECUNIA
SUSE-SR:2006:009
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now