PT-2005-1985 · Horde · Horde

Publicado

2005-04-03

·

Atualizado

2008-09-05

·

CVE-2005-0961

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Horde version 3.0.4
Description A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via the parent frame title. This could potentially lead to unauthorized actions on the affected system.
Recommendations For Horde version 3.0.4, update to 3.0.4-RC2 or later to resolve the issue. As a temporary workaround, consider restricting access to the parent frame title to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-0961

Produtos afetados

Horde