CVE-2005-3759

Publication date 22 November 2005

Last updated 24 July 2024


Ubuntu priority

Multiple cross-site scripting (XSS) vulnerabilities in Horde before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) gzip/tar and (2) css MIME viewers, which do not filter or escape dangerous HTML when extracting and displaying attachments.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
horde3 7.04 feisty
Fixed 3.1.1-1
6.10 edgy
Fixed 3.1.1-1
6.06 LTS dapper
Fixed 3.1.1-1