Horde IMP 4.0.4 and earlier does not sanitize strings containing UTF16 null characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via UTF16 encoded attachments and strings that will be executed when viewed using Internet Explorer, which ignores the characters.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2005-12-08 01:03
Updated : 2025-04-03 01:03
NVD link : CVE-2005-4080
Mitre link : CVE-2005-4080
CVE.ORG link : CVE-2005-4080
JSON object : View
Products Affected
horde
- imp
CWE