4.3
CVSSv2

CVE-2010-3695

Published: 31/03/2011 Updated: 18/06/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in fetchmailprefs.php in Horde IMP prior to 4.3.8, and Horde Groupware Webmail Edition prior to 1.2.7, allows remote malicious users to inject arbitrary web script or HTML via the fm_id parameter in a fetchmail_prefs_save action, related to the Fetchmail configuration.

Vulnerable Product Search on Vulmon Subscribe to Product

horde imp 4.1.3

horde imp 4.0.4

horde imp 2.2.1

horde imp 4.1.5

horde imp 4.0.3

horde imp 2.2.5

horde imp 4.3.5

horde imp 4.2.2

horde imp 4.3

horde imp 4.3.2

horde imp 3.2.7

horde imp 3.2

horde imp 3.1.2

horde imp 3.2.2

horde imp 2.2.2

horde imp 2.0

horde imp 4.3.3

horde imp 3.2.4

horde imp 3.2.3

horde imp 2.2.8

horde imp 3.1

horde imp 4.0.2

horde imp 4.1.6

horde imp 2.2.6

horde imp 2.2.7

horde imp 2.2

horde imp 4.2

horde imp 4.2.1

horde imp 4.0.1

horde imp 4.0

horde imp 3.2.1

horde imp 2.3

horde imp 2.2.4

horde imp 4.3.6

horde imp 2.2.3

horde imp 4.3.4

horde imp 4.3.1

horde imp 3.2.6

horde imp 3.2.5

horde imp 3.0

horde imp

horde groupware 1.1

horde groupware 1.0

horde groupware 1.2.3

horde groupware 1.2.2

horde groupware 1.0.4

horde groupware 1.1.4

horde groupware 1.0.7

horde groupware 1.1.6

horde groupware 1.1.3

horde groupware 1.2.5

horde groupware 1.0.8

horde groupware 1.1.1

horde groupware 1.2

horde groupware 1.0.3

horde groupware 1.2.4

horde groupware 1.0.2

horde groupware 1.2.1

horde groupware 1.1.2

horde groupware 1.0.5

horde groupware 1.1.5

horde groupware 1.0.6

horde groupware 1.0.1

horde groupware

Vendor Advisories

Moritz Naumann discovered that IMP 4, a webmail component for the Horde framework, is prone to cross-site scripting attacks by a lack of input sanitising of certain Fetchmail information For the oldstable distribution (lenny), this problem has been fixed in version 42-4lenny3 For the stable distribution (squeeze), this problem has been fixed in ...

Exploits

source: wwwsecurityfocuscom/bid/43515/info Horde IMP Webmail is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied data before it is used in dynamic content Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal coo ...