CVE Vulnerabilities

CVE-2007-1679

Published: Mar 26, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
NEGLIGIBLE
root.io logo minimus.io logo echo.ai logo

Multiple cross-site scripting (XSS) vulnerabilities in Horde Groupware Webmail 1.0 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors in (1) imp/search.php and (2) ingo/rule.php. NOTE: this issue has been disputed by the vendor, noting that the search.php issue was resolved in CVE-2006-4255, and attackers can only use rule.php to inject XSS into their own pages

Affected Software

NameVendorStart VersionEnd Version
GroupwareHorde1.0 (including)1.0 (including)
Horde3Ubuntudapper*
Horde3Ubuntudevel*
Horde3Ubuntuedgy*
Horde3Ubuntufeisty*
Horde3Ubuntugutsy*
Horde3Ubuntuhardy*
Horde3Ubuntuintrepid*
Horde3Ubuntujaunty*
Horde3Ubuntuupstream*

References