MEDIUM
imp: XSS attack
Published Sep 23, 2008
4.3
MEDIUMCVSS 2.0
EPSS 1.30%
Description
Cross-site scripting (XSS) vulnerability in imp/test.php in Horde Turba Contact Manager H3 2.2.1 and other versions before 2.3.1, and possibly other Horde Project products, allows remote attackers to inject arbitrary web script or HTML via the User field in an IMAP session.
Affected products
No data.
OR
- 2.2.1
- 3.1.1
- 3.2.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (11)
- http://lists.horde.org/archives/announce/2008/000465.html mailing-listx_refsource_MLIST
- http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html vendor-advisoryx_refsource_SUSE
- http://packetstormsecurity.org/0809-exploits/turba-xss.txt x_refsource_MISC
- http://secunia.com/advisories/34703 third-party-advisoryx_refsource_SECUNIA
- http://www.debian.org/security/2009/dsa-1770 vendor-advisoryx_refsource_DEBIAN
- http://www.securityfocus.com/bid/31168 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2008-4182 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=464210 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45131 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2008-4182
- https://www.cve.org/CVERecord?id=CVE-2008-4182
| Link | Providers | Tags |
|---|---|---|
| http://lists.horde.org/archives/announce/2008/000465.html | mailing-listx_refsource_MLIST | |
| http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html | vendor-advisoryx_refsource_SUSE | |
| http://packetstormsecurity.org/0809-exploits/turba-xss.txt | x_refsource_MISC | |
| http://secunia.com/advisories/34703 | third-party-advisoryx_refsource_SECUNIA | |
| http://www.debian.org/security/2009/dsa-1770 | vendor-advisoryx_refsource_DEBIAN | |
| http://www.securityfocus.com/bid/31168 | vdb-entryx_refsource_BID | |
| https://access.redhat.com/security/cve/CVE-2008-4182 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=464210 | Issue Tracking | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/45131 | vdb-entryx_refsource_XF | |
| https://nvd.nist.gov/vuln/detail/CVE-2008-4182 | ||
| https://www.cve.org/CVERecord?id=CVE-2008-4182 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 23, 2008
Updated Aug 7, 2024
Reserved Sep 23, 2008
Link CVE-2008-4182
CISA Vulnrichment
Updated n/a