CVE-2005-3570
Published Nov 16, 2005
Last updated 13 years ago
Overview
- Description
- Unspecified cross-site scripting (XSS) vulnerability in Horde before 2.2.9 allows remote attackers to inject arbitrary web script or HTML via "not properly escaped error messages".
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:horde:horde:2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "064985D4-266B-4EEF-9BA2-B4F6EF22665F" }, { "criteria": "cpe:2.3:a:horde:horde:2.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "03528181-D73F-473B-BA15-9052228690BD" }, { "criteria": "cpe:2.3:a:horde:horde:2.2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6C592CD2-2836-4892-BB78-E794E5169009" }, { "criteria": "cpe:2.3:a:horde:horde:2.2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E41299B1-934C-4CD8-A956-D12EFA0B1916" }, { "criteria": "cpe:2.3:a:horde:horde:2.2.4_rc1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "56D3EBB9-CB0F-4C5A-BED1-0DF781197E5E" }, { "criteria": "cpe:2.3:a:horde:horde:2.2.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "14A94F9F-C39E-4A31-87DD-CA1248FAC299" }, { "criteria": "cpe:2.3:a:horde:horde:2.2.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A0116F7F-D0EF-4E1A-97F8-F9D8BD0364EC" }, { "criteria": "cpe:2.3:a:horde:horde:2.2.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "94B640CC-3623-4D11-A542-02A401AC814D" }, { "criteria": "cpe:2.3:a:horde:horde:2.2.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CDC11155-F78F-4C6A-B5CF-AA757996320A" } ], "operator": "OR" } ] } ]