Page 3 of 23 results (0.011 seconds)

CVSS: 4.3EPSS: 1%CPEs: 25EXPL: 2

Horde IMP 4.0.4 and earlier does not sanitize strings containing UTF16 null characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via UTF16 encoded attachments and strings that will be executed when viewed using Internet Explorer, which ignores the characters. • https://www.exploit-db.com/exploits/26741 http://secunia.com/advisories/17910 http://securityreason.com/securityalert/232 http://securitytracker.com/id?1015315 http://www.securityfocus.com/archive/1/418734/100/0/threaded http://www.securityfocus.com/bid/15730 http://www.vupen.com/english/advisories/2005/2773 https://exchange.xforce.ibmcloud.com/vulnerabilities/23465 •

CVSS: 4.3EPSS: 0%CPEs: 7EXPL: 0

Cross-site scripting (XSS) vulnerability in Horde IMP Webmail client before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title. • http://cvs.horde.org/diff.php/imp/docs/CHANGES?r1=1.389.2.119&r2=1.389.2.125&ty=h http://lists.horde.org/archives/imp/Week-of-Mon-20050418/041912.html http://secunia.com/advisories/15080 •

CVSS: 4.3EPSS: 0%CPEs: 19EXPL: 0

Cross-site scripting (XSS) vulnerability in the inline MIME viewer in Horde-IMP (Internet Messaging Program) 3.2.4 and earlier, when used with Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via an e-mail message. • http://cvs.horde.org/diff.php/imp/docs/CHANGES?r1=1.389.2.106&r2=1.389.2.109&ty=h http://secunia.com/advisories/12202 http://www.gentoo.org/security/en/glsa/glsa-200408-07.xml http://www.securityfocus.com/bid/10845 https://exchange.xforce.ibmcloud.com/vulnerabilities/16866 •

CVSS: 6.8EPSS: 2%CPEs: 18EXPL: 0

Unknown vulnerability in Horde IMP 3.2.3 and earlier, before a "security fix," does not properly validate input, which allows remote attackers to execute arbitrary script as other users via script or HTML in an e-mail message, possibly triggering a cross-site scripting (XSS) vulnerability. Vulnerabilidad desconocida en Hored-IMP 3.2.3 y anteriores, antes de un "arreglo de seguridad" no validan adecuadamente la entrada, lo que permite a atacantes remotos ejecutar script de su elección como otro usuario mediante script o HTML, posiblemente disparando una vulnerabilidad de secuencias de comandos en sitios cruzados (XSS). • http://secunia.com/advisories/11805 http://www.gentoo.org/security/en/glsa/glsa-200406-11.xml http://www.horde.org/imp/3.2 http://www.securityfocus.com/bid/10501 https://exchange.xforce.ibmcloud.com/vulnerabilities/16357 •

CVSS: 7.5EPSS: 0%CPEs: 9EXPL: 0

Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possibly gain privileges via certain database functions such as check_prefs() in db.pgsql, as demonstrated using mailbox.php3. Múltiples vulnerabilidades de inyección de SQL en IMP 2.2.8 y anteriores permiten a atacantes remotos llevar a cabo actividades no autorizadas en la base de datos y posiblemente ganar privilegios mediante ciertas funcines de la base de datos como check_prefs() en db.pgsql, como se demostrado usando mailbox.php3. • http://marc.info/?l=bugtraq&m=104204786206563&w=2 http://secunia.com/advisories/8087 http://secunia.com/advisories/8177 http://www.debian.org/security/2003/dsa-229 http://www.securityfocus.com/archive/1/306268 http://www.securityfocus.com/bid/6559 http://www.securitytracker.com/id?1005904 •