Total vulnerabilities in the database
Cross-site scripting vulnerability in status.php3 for IMP 2.2.8 and HORDE 1.2.7 allows remote attackers to execute arbitrary web script and steal cookies of other IMP/HORDE users via the script parameter.
Software | From | Fixed in |
---|---|---|
horde / imp | 2.2.8 | 2.2.8.x |
horde / horde | 1.2.7 | 1.2.7.x |