UBUNTU-CVE-2014-4945
Dashboard / Vulnerabilities / UBUNTU-CVE-2014-4945
Summary:
Details: Multiple cross-site scripting (XSS) vulnerabilities in Horde Internet Mail Program (IMP) before 6.1.8, as used in Horde Groupware Webmail Edition before 5.1.5, allow remote attackers to inject arbitrary web script or HTML via an unspecified flag in the basic (1) mailbox or (2) message view.
References: https://ubuntu.com/security/CVE-2014-4945, https://github.com/horde/horde/blob/c0144ac03814a8c2cf6fc5ac0d1af2653e9ee139/imp/docs/CHANGES, https://github.com/horde/horde/blob/4513649810f13a32f1193bdeed76f7d85a5efa05/bundles/webmail/docs/CHANGES, http://secunia.com/advisories/59772, http://secunia.com/advisories/59770, http://lists.horde.org/archives/announce/2014/001025.html, http://lists.horde.org/archives/announce/2014/001019.html, https://www.cve.org/CVERecord?id=CVE-2014-4945
Affected packages
Package
Name: php-horde-imp
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
