CVE Vulnerabilities

CVE-2004-0584

Published: Aug 06, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Unknown vulnerability in Horde IMP 3.2.3 and earlier, before a security fix, does not properly validate input, which allows remote attackers to execute arbitrary script as other users via script or HTML in an e-mail message, possibly triggering a cross-site scripting (XSS) vulnerability.

Affected Software

NameVendorStart VersionEnd Version
ImpHorde2.0 (including)2.0 (including)
ImpHorde2.2 (including)2.2 (including)
ImpHorde2.2.1 (including)2.2.1 (including)
ImpHorde2.2.2 (including)2.2.2 (including)
ImpHorde2.2.3 (including)2.2.3 (including)
ImpHorde2.2.4 (including)2.2.4 (including)
ImpHorde2.2.5 (including)2.2.5 (including)
ImpHorde2.2.6 (including)2.2.6 (including)
ImpHorde2.2.7 (including)2.2.7 (including)
ImpHorde2.2.8 (including)2.2.8 (including)
ImpHorde2.3 (including)2.3 (including)
ImpHorde3.0 (including)3.0 (including)
ImpHorde3.1 (including)3.1 (including)
ImpHorde3.1.2 (including)3.1.2 (including)
ImpHorde3.2 (including)3.2 (including)
ImpHorde3.2.1 (including)3.2.1 (including)
ImpHorde3.2.2 (including)3.2.2 (including)
ImpHorde3.2.3 (including)3.2.3 (including)

References