Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting vulnerability in status.php3 for IMP 2.2.8 and HORDE 1.2.7 allows remote attackers to execute arbitrary web script and steal cookies of other IMP/HORDE users via the script parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Horde IMP 2.2.7存在跨站脚本执行漏洞
Vulnerability Description
IMP是一款基于Web的强大的邮件程序,它由Horde项目组开发。可使用在Linux/Unix或者Microsoft Windows操作系统下。 Horde IMP在处理用户提交的内容上过滤不充分,可导致跨站脚本执行漏洞。 Horde IMPd的status.php3脚本没有充分检查用户输入的内容,如HTML标记等,攻击者可插入任意脚本代码作为参数提交给status.php3脚本,当其他用户浏览这个链接时就可以导致脚本在用户浏览器上执行,可导致基于Cookie认证的信息被泄露。
CVSS Information
N/A
Vulnerability Type
N/A