Vulnerability Name: | CVE-2005-4191 (CCN-23619) | ||||||||
Assigned: | 2005-12-11 | ||||||||
Published: | 2005-12-11 | ||||||||
Updated: | 2011-03-08 | ||||||||
Summary: | Multiple cross-site scripting (XSS) vulnerabilities in templates/tasklists/tasklists.inc in Horde Nag Task List Manager H3 before 2.0.4 allow remote authenticated users to inject arbitrary web script or HTML via (1) the tasklist's name or (2) description, when creating a new tasklist. | ||||||||
CVSS v3 Severity: | 2.6 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Sun Dec 11 2005 - 14:04:30 CST SEC Consult SA-20051211-0 :: Several XSS issues in Horde Framework, Kronolith Calendar, Mnemo Notes, Nag Tasks and Turba Addressbook Source: MITRE Type: CNA CVE-2005-4191 Source: CONFIRM Type: Patch http://cvs.horde.org/diff.php/nag/templates/tasklists/tasklists.inc?r1=1.10&r2=1.11&ty=h Source: MLIST Type: Patch [horde-announce] 20051211 Nag H3 (2.0.4) (final) Source: CCN Type: SA17969 Nag Script Insertion Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory 17969 Source: CCN Type: Horde Web site The Horde Application Framework Source: CCN Type: OSVDB ID: 21603 Horde Nag Application Task Lists Multiple Field XSS Source: MISC Type: Vendor Advisory http://www.sec-consult.com/245.html Source: BID Type: UNKNOWN 15804 Source: CCN Type: BID-15804 Horde Nag Remote HTML Injection Vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2005-2836 Source: XF Type: UNKNOWN horde-multiple-template-xss(23619) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |