Vulnerabilities > Horde > Turba H3 > 2.0.1

DATE CVE VULNERABILITY TITLE RISK
2009-04-23 CVE-2008-6746 Cross-Site Scripting vulnerability in Horde Turba H3
Cross-site scripting (XSS) vulnerability in the contact display view in Turba Contact Manager H3 before 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the contact name.
network
horde CWE-79
4.3
2005-12-14 CVE-2005-4242 Cross-Site Scripting vulnerability in Turba H3
Multiple cross-site scripting (XSS) vulnerabilities in Horde Turba H3 2.0.4 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the address book and (2) contact data.
network
horde
4.3