CVE-2005-3759
Publication date 22 November 2005
Last updated 24 July 2024
Ubuntu priority
Multiple cross-site scripting (XSS) vulnerabilities in Horde before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) gzip/tar and (2) css MIME viewers, which do not filter or escape dangerous HTML when extracting and displaying attachments.
Status
Package | Ubuntu Release | Status |
---|---|---|
horde3 | 7.04 feisty |
Fixed 3.1.1-1
|
6.10 edgy |
Fixed 3.1.1-1
|
|
6.06 LTS dapper |
Fixed 3.1.1-1
|