Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP H3 4.1.3, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via (1) the email Subject header in thread.php, (2) the edit_query parameter in search.php, or other unspecified parameters in search.php. NOTE: some of these details are obtained from third party information.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Horde IMP 多个跨站脚本攻击漏洞
Vulnerability Description
Horde IMP H3 4.1.3以及可能之前版本中存在多个跨站脚本攻击漏洞。远程攻击者可以借助thread.php文件中的(1)电子邮件主题标头、search.php中的(2)edit_query参数或search.php中的其他未明参数,注入任意的web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A