Vulnerabilities > CVE-2007-1515 - Input Validation vulnerability in Horde IMP Webmail Client

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
horde
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP H3 4.1.3, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via (1) the email Subject header in thread.php, (2) the edit_query parameter in search.php, or other unspecified parameters in search.php. NOTE: some of these details are obtained from third party information.

Exploit-Db

descriptionHorde IMP Webmail 4.0.4 Client Multiple Input Validation Vulnerabilities. CVE-2007-1515 . Webapps exploit for php platform
idEDB-ID:29742
last seen2016-02-03
modified2007-03-15
published2007-03-15
reporterImmerda Project Group
sourcehttps://www.exploit-db.com/download/29742/
titleHorde IMP Webmail <= 4.0.4 Client Multiple Input Validation Vulnerabilities