CVE-2005-3570

Unspecified cross-site scripting (XSS) vulnerability in Horde before 2.2.9 allows remote attackers to inject arbitrary web script or HTML via "not properly escaped error messages".
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:horde:horde:2.2:*:*:*:*:*:*:*
cpe:2.3:a:horde:horde:2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:horde:horde:2.2.3:*:*:*:*:*:*:*
cpe:2.3:a:horde:horde:2.2.4:*:*:*:*:*:*:*
cpe:2.3:a:horde:horde:2.2.4_rc1:*:*:*:*:*:*:*
cpe:2.3:a:horde:horde:2.2.5:*:*:*:*:*:*:*
cpe:2.3:a:horde:horde:2.2.6:*:*:*:*:*:*:*
cpe:2.3:a:horde:horde:2.2.7:*:*:*:*:*:*:*
cpe:2.3:a:horde:horde:2.2.8:*:*:*:*:*:*:*

History

21 Nov 2024, 00:02

Type Values Removed Values Added
References () http://cvs.horde.org/diff.php/horde/docs/CHANGES?r1=1.207.2.109&r2=1.207.2.111&ty=h - Patch () http://cvs.horde.org/diff.php/horde/docs/CHANGES?r1=1.207.2.109&r2=1.207.2.111&ty=h - Patch
References () http://lists.horde.org/archives/announce/2005/000231.html - () http://lists.horde.org/archives/announce/2005/000231.html -
References () http://secunia.com/advisories/17468 - Patch, Vendor Advisory () http://secunia.com/advisories/17468 - Patch, Vendor Advisory
References () http://secunia.com/advisories/17702 - Patch, Vendor Advisory () http://secunia.com/advisories/17702 - Patch, Vendor Advisory
References () http://secunia.com/advisories/17794 - Patch, Vendor Advisory () http://secunia.com/advisories/17794 - Patch, Vendor Advisory
References () http://www.debian.org/security/2005/dsa-914 - Patch, Vendor Advisory () http://www.debian.org/security/2005/dsa-914 - Patch, Vendor Advisory
References () http://www.gentoo.org/security/en/glsa/glsa-200511-20.xml - Patch, Vendor Advisory () http://www.gentoo.org/security/en/glsa/glsa-200511-20.xml - Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/15409 - Patch () http://www.securityfocus.com/bid/15409 - Patch
References () http://www.vupen.com/english/advisories/2005/2403 - Vendor Advisory () http://www.vupen.com/english/advisories/2005/2403 - Vendor Advisory

Information

Published : 2005-11-16 07:42

Updated : 2024-11-21 00:02


NVD link : CVE-2005-3570

Mitre link : CVE-2005-3570

CVE.ORG link : CVE-2005-3570


JSON object : View

Products Affected

horde

  • horde
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')