Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP before 5.0.18 and Horde Groupware Webmail Edition before 4.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) composeCache, (2) rtemode, or (3) filename_* parameters to the compose page; (4) formname parameter to the contacts popup window; or (5) IMAP mailbox names. NOTE: some of these details are obtained from third party information.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Horde Groupware Webmail 跨站脚本漏洞
Vulnerability Description
Horde Groupware Webmail是美国Horde公司的一套基于浏览器的企业级通信套件。 Horde IMP 5.0.18之前版本与 Horde Groupware Webmail Edition 4.0.6之前版本中存在跨站脚本漏洞。远程攻击者可利用该漏洞借助(1) composeCache或(2) rtemode等注入任意web脚本或者HTML。
CVSS Information
N/A
Vulnerability Type
N/A