UBUNTU-CVE-2014-4946
Dashboard / Vulnerabilities / UBUNTU-CVE-2014-4946
Summary:
Details: Multiple cross-site scripting (XSS) vulnerabilities in Horde Internet Mail Program (IMP) before 6.1.8, as used in Horde Groupware Webmail Edition before 5.1.5, allow remote attackers to inject arbitrary web script or HTML via (1) unspecified flags or (2) a mailbox name in the dynamic mailbox view.
References: https://ubuntu.com/security/CVE-2014-4946, https://github.com/horde/horde/blob/c0144ac03814a8c2cf6fc5ac0d1af2653e9ee139/imp/docs/CHANGES, https://github.com/horde/horde/blob/4513649810f13a32f1193bdeed76f7d85a5efa05/bundles/webmail/docs/CHANGES, http://secunia.com/advisories/59772, http://secunia.com/advisories/59770, http://lists.horde.org/archives/announce/2014/001025.html, http://lists.horde.org/archives/announce/2014/001019.html, https://www.cve.org/CVERecord?id=CVE-2014-4946
Affected packages
Package
Name: php-horde-imp
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
