Executive Summary
This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Informations | |||
---|---|---|---|
Name | CVE-2009-0930 | First vendor Publication | 2009-03-17 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:N/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 4.3 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP before 4.2.2 and 4.3.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) smime.php, (2) pgp.php, and (3) message.php. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0930 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') (CWE/SANS Top 25) |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:13528 | |||
Oval ID: | oval:org.mitre.oval:def:13528 | ||
Title: | DSA-1770-1 imp4 -- Insufficient input sanitising | ||
Description: | Several vulnerabilities have been found in imp4, a webmail component for the horde framework. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2008-4182 It was discovered that imp4 suffers from a cross-site scripting attack via the user field in an IMAP session, which allows attackers to inject arbitrary HTML code. CVE-2009-0930 It was discovered that imp4 is prone to several cross-site scripting attacks via several vectors in the mail code allowing attackers to inject arbitrary HTML code. For the oldstable distribution, these problems have been fixed in version 4.1.3-4etch1. For the stable distribution, these problems have been fixed in version 4.2-4, which was already included in the lenny release. For the testing distribution and the unstable distribution, these problems have been fixed in version 4.2-4. We recommend that you upgrade your imp4 packages. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-1770-1 CVE-2008-4182 CVE-2009-0930 | Version: | 5 |
Platform(s): | Debian GNU/Linux 4.0 | Product(s): | imp4 |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:8083 | |||
Oval ID: | oval:org.mitre.oval:def:8083 | ||
Title: | DSA-1770 imp4 -- Insufficient input sanitising | ||
Description: | Several vulnerabilities have been found in imp4, a webmail component for the horde framework. The Common Vulnerabilities and Exposures project identifies the following problems: It was discovered that imp4 suffers from a cross-site scripting (XSS) attack via the user field in an IMAP session, which allows attackers to inject arbitrary HTML code. It was discovered that imp4 is prone to several cross-site scripting (XSS) attacks via several vectors in the mail code allowing attackers to inject arbitrary HTML code. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-1770 CVE-2008-4182 CVE-2009-0930 | Version: | 3 |
Platform(s): | Debian GNU/Linux 4.0 | Product(s): | imp4 |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 |
OpenVAS Exploits
Date | Description |
---|---|
2010-04-06 | Name : Fedora Update for imp FEDORA-2010-5508 File : nvt/gb_fedora_2010_5508_imp_fc11.nasl |
2009-09-15 | Name : Gentoo Security Advisory GLSA 200909-14 (horde horde-imp horde-passwd) File : nvt/glsa_200909_14.nasl |
2009-04-15 | Name : Debian Security Advisory DSA 1770-1 (imp4) File : nvt/deb_1770_1.nasl |
2009-03-31 | Name : SuSE Security Summary SUSE-SR:2009:007 File : nvt/suse_sr_2009_007.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
51828 | IMP message.php Unspecified Parameter XSS IMP contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate unspecified parameters upon submission to the message.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity. |
51827 | IMP pgp.php Unspecified Parameter XSS IMP contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate unspecified parameters upon submission to the pgp.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity. |
51826 | IMP smime.php Unspecified Parameter XSS IMP contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate unspecified parameters upon submission to the smime.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2010-07-01 | Name : The remote Fedora host is missing a security update. File : fedora_2010-5508.nasl - Type : ACT_GATHER_INFO |
2009-09-14 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200909-14.nasl - Type : ACT_GATHER_INFO |
2009-07-21 | Name : The remote openSUSE host is missing a security update. File : suse_11_0_imp-090318.nasl - Type : ACT_GATHER_INFO |
2009-04-14 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1770.nasl - Type : ACT_GATHER_INFO |
2009-03-24 | Name : The remote openSUSE host is missing a security update. File : suse_imp-6101.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:11:52 |
|
2024-11-28 12:18:31 |
|
2021-05-04 12:09:16 |
|
2021-04-22 01:09:37 |
|
2020-05-23 01:40:10 |
|
2020-05-23 00:23:30 |
|
2016-04-26 18:42:03 |
|
2014-02-17 10:49:15 |
|
2013-05-10 23:46:44 |
|