CVE-2005-4190
Last modified
CVE-2005-4190 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in Horde Application Framework before 3.0.8 allow remote authenticated users to inject arbitrary web script or HTML via multiple vectors, as demonstrated by (1) the identity field, (2) Category and (3) Label search fields, (4) the Mobile Phone field, and (5) Date and (6) Time fields when importing CSV files, as exploited through modules such as (a) Turba Address Book, (b) Kronolith, (c) Mnemo, and (d) Nag.. EPSS estimates a 1.60% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Horde Application Framework before 3.0.8 allow remote authenticated users to inject arbitrary web script or HTML via multiple vectors, as demonstrated by (1) the identity field, (2) Category and (3) Label search fields, (4) the Mobile Phone field, and (5) Date and (6) Time fields when importing CSV files, as exploited through modules such as (a) Turba Address Book, (b) Kronolith, (c) Mnemo, and (d) Nag.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Horde | Horde Application Framework | 1.0.0 |
| Horde | Horde Application Framework | 1.0.2 |
| Horde | Horde Application Framework | 1.0.2_1 |
| Horde | Horde Application Framework | 1.0.3 |
| Horde | Horde Application Framework | 1.0.3_2 |
| Horde | Horde Application Framework | 1.0.3_3 |
| Horde | Horde Application Framework | 1.0.3_4 |
| Horde | Horde Application Framework | 1.0.4 |
| Horde | Horde Application Framework | 1.0.5 |
| Horde | Horde Application Framework | 1.0.6 |
| Horde | Horde Application Framework | 1.0.8 |
| Horde | Horde Application Framework | 1.0.9 |
| Horde | Horde Application Framework | 1.0.10 |
| Horde | Horde Application Framework | 1.0.11 |
| Horde | Horde Application Framework | 1.2.0 |
| Horde | Horde Application Framework | 1.2.1 |
| Horde | Horde Application Framework | 1.2.2 |
| Horde | Horde Application Framework | 1.2.3 |
| Horde | Horde Application Framework | 1.2.4 |
| Horde | Horde Application Framework | 1.2.5 |
| Horde | Horde Application Framework | 1.2.6 |
| Horde | Horde Application Framework | 1.2.7 |
| Horde | Horde Application Framework | 1.2.8 |
| Horde | Horde Application Framework | 1.3.3 |
| Horde | Horde Application Framework | 1.3.4 |
| Horde | Horde Application Framework | 2.0 |
| Horde | Horde Application Framework | 2.1 |
| Horde | Horde Application Framework | 2.2 |
| Horde | Horde Application Framework | 2.2.1 |
| Horde | Horde Application Framework | 2.2.3 |
| Horde | Horde Application Framework | 2.2.4 |
| Horde | Horde Application Framework | 2.2.5 |
| Horde | Horde Application Framework | 2.2.6 |
| Horde | Horde Application Framework | 2.2.7 |
| Horde | Horde Application Framework | 2.2.8 |
| Horde | Horde Application Framework | 2.2.9 |
| Horde | Horde Application Framework | 3.0.1 |
| Horde | Horde Application Framework | 3.0.2 |
| Horde | Horde Application Framework | 3.0.3 |
| Horde | Horde Application Framework | 3.0.4 |
| Horde | Horde Application Framework | 3.0.5 |
| Horde | Horde Application Framework | 3.0.6 |
| Horde | Horde Application Framework | 3.0.7 |
References
- http://secunia.com/advisories/17970Patch, Vendor Advisory
- http://secunia.com/advisories/19619Vendor Advisory
- http://secunia.com/advisories/19897Vendor Advisory
- http://secunia.com/advisories/20960Vendor Advisory
- http://www.vupen.com/english/advisories/2005/2835Vendor Advisory
- http://secunia.com/advisories/17970Patch, Vendor Advisory
- http://secunia.com/advisories/19619Vendor Advisory
- http://secunia.com/advisories/19897Vendor Advisory
- http://secunia.com/advisories/20960Vendor Advisory
- http://www.vupen.com/english/advisories/2005/2835Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-4190?
How severe is CVE-2005-4190?
How do I fix CVE-2005-4190?
Are you affected by CVE-2005-4190?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
