CVE-2008-4182

NameCVE-2008-4182
DescriptionCross-site scripting (XSS) vulnerability in imp/test.php in Horde Turba Contact Manager H3 2.2.1 and other versions before 2.3.1, and possibly other Horde Project products, allows remote attackers to inject arbitrary web script or HTML via the User field in an IMAP session.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-1770-1
Debian Bugs500114, 500553

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
imp4sourceetch4.1.3-4etch1DSA-1770-1
imp4source(unstable)4.2-3low500553
turba2source(unstable)2.2.1-2low500114

Notes

[etch] - turba2 <no-dsa> (Minor issue)

Search for package or bug name: Reporting problems