Cross-site scripting (XSS) vulnerability in Horde IMP Webmail client before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via the parents frame page title.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Imp | Horde | * | 3.2.2 (including) |
Imp | Horde | 3.2.3 (including) | 3.2.3 (including) |
Imp | Horde | 3.2.4 (including) | 3.2.4 (including) |
Imp | Horde | 3.2.5 (including) | 3.2.5 (including) |
Imp | Horde | 3.2.6 (including) | 3.2.6 (including) |
Imp | Horde | 3.2.7 (including) | 3.2.7 (including) |
Imp | Horde | 3.2.7_rc1 (including) | 3.2.7_rc1 (including) |
Imp3 | Ubuntu | dapper | * |
Imp3 | Ubuntu | edgy | * |