CVE-2005-4192

Multiple cross-site scripting (XSS) vulnerabilities in templates/notepads/notepads.inc in Horde Mnemo Note Manager H3 before 2.0.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) the notepad's name or (2) description, when creating a new notepad.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:horde:mnemo_note_manager_h3:2.0:*:*:*:*:*:*:*
cpe:2.3:a:horde:mnemo_note_manager_h3:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:horde:mnemo_note_manager_h3:2.0.2:*:*:*:*:*:*:*

History

21 Nov 2024, 00:03

Type Values Removed Values Added
References () http://cvs.horde.org/diff.php/mnemo/templates/notepads/notepads.inc?r1=1.9&r2=1.10&ty=h - Patch () http://cvs.horde.org/diff.php/mnemo/templates/notepads/notepads.inc?r1=1.9&r2=1.10&ty=h - Patch
References () http://lists.horde.org/archives/announce/2005/000237.html - Patch () http://lists.horde.org/archives/announce/2005/000237.html - Patch
References () http://secunia.com/advisories/17964 - Patch, Vendor Advisory () http://secunia.com/advisories/17964 - Patch, Vendor Advisory
References () http://www.sec-consult.com/245.html - Exploit, Vendor Advisory () http://www.sec-consult.com/245.html - Exploit, Vendor Advisory
References () http://www.securityfocus.com/bid/15803 - Patch () http://www.securityfocus.com/bid/15803 - Patch
References () http://www.vupen.com/english/advisories/2005/2833 - () http://www.vupen.com/english/advisories/2005/2833 -

Information

Published : 2005-12-13 11:03

Updated : 2024-11-21 00:03


NVD link : CVE-2005-4192

Mitre link : CVE-2005-4192

CVE.ORG link : CVE-2005-4192


JSON object : View

Products Affected

horde

  • mnemo_note_manager_h3