CVE-2005-3759
Last modified
CVE-2005-3759 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in Horde before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) gzip/tar and (2) css MIME viewers, which do not filter or escape dangerous HTML when extracting and displaying attachments.. EPSS estimates a 1.44% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Horde before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) gzip/tar and (2) css MIME viewers, which do not filter or escape dangerous HTML when extracting and displaying attachments.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Horde | Horde | 1.2 |
| Horde | Horde | 1.2.1 |
| Horde | Horde | 1.2.2 |
| Horde | Horde | 1.2.3 |
| Horde | Horde | 1.2.4 |
| Horde | Horde | 1.2.5 |
| Horde | Horde | 1.2.6 |
| Horde | Horde | 1.2.7 |
| Horde | Horde | 1.2.8 |
| Horde | Horde | 2.0 |
| Horde | Horde | 2.1 |
| Horde | Horde | 2.1.3 |
| Horde | Horde | 2.2 |
| Horde | Horde | 2.2.1 |
| Horde | Horde | 2.2.3 |
| Horde | Horde | 2.2.4 |
| Horde | Horde | 2.2.4_rc1 |
| Horde | Horde | 2.2.5 |
| Horde | Horde | 2.2.6 |
| Horde | Horde | 2.2.7 |
| Horde | Horde | 2.2.8 |
| Horde | Horde | 2.2.9 |
| Horde | Horde | 3.0 |
| Horde | Horde | 3.0.1 |
| Horde | Horde | 3.0.2 |
| Horde | Horde | 3.0.3 |
| Horde | Horde | 3.0.4 |
| Horde | Horde | 3.0.4_rc1 |
| Horde | Horde | 3.0.4_rc2 |
| Horde | Horde | 3.0.6 |
| Horde | Horde | 3.0.7 |
References
- http://secunia.com/advisories/17599Patch, Vendor Advisory
- http://secunia.com/advisories/17703Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2005/2536Vendor Advisory
- http://secunia.com/advisories/17599Patch, Vendor Advisory
- http://secunia.com/advisories/17703Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2005/2536Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-3759?
How severe is CVE-2005-3759?
How do I fix CVE-2005-3759?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-3753Linux kernel before after 2.6.12 and before 2.6.13.1 might a…
- CVE-2005-3754Cross-site scripting (XSS) vulnerability in Google Mini Sear…
- CVE-2005-3755Directory traversal vulnerability in Google Mini Search Appl…
- CVE-2005-3756Google Mini Search Appliance, and possibly Google Search App…
- CVE-2005-3757The Saxon XSLT parser in Google Mini Search Appliance, and p…
- CVE-2005-3758Cross-site scripting (XSS) vulnerability in Google Mini Sear…
- CVE-2005-3760Double free vulnerability in the BBOORB module in IBM WebSph…
- CVE-2005-3761Cross-site scripting (XSS) vulnerability in Exponent CMS 0.9…
- CVE-2005-3762SQL injection vulnerability in the navigation module (naviga…
- CVE-2005-3763Exponent CMS 0.96.3 and later versions includes the full ins…
- CVE-2005-3764The image gallery (imagegallery) component in Exponent CMS 0…
- CVE-2005-3765Exponent CMS 0.96.3 and later versions performs a chmod on u…
Are you affected by CVE-2005-3759?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
