Vulnerabilities > CVE-2005-4080 - Unspecified vulnerability in Horde IMP

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
horde
exploit available

Summary

Horde IMP 4.0.4 and earlier does not sanitize strings containing UTF16 null characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via UTF16 encoded attachments and strings that will be executed when viewed using Internet Explorer, which ignores the characters.

Exploit-Db

descriptionHorde IMP 2.2.x/3.2.x/4.0.x Email Attachments HTML Injection Vulnerability. CVE-2005-4080 . Remote exploit for linux platform
idEDB-ID:26741
last seen2016-02-03
modified2005-12-06
published2005-12-06
reporterSEC Consult
sourcehttps://www.exploit-db.com/download/26741/
titleHorde IMP 2.2.x/3.2.x/4.0.x Email Attachments HTML Injection Vulnerability