CVE-2012-6620 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in the (1) tasks and (2) search views in Horde Kronolith H4 before 3.0.17 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Reference

http://bugs.horde.org/ticket/11189 http://lists.horde.org/archives/announce/2012/000766.html http://secunia.com/advisories/49147 http://www.securityfocus.com/bid/53731 https://exchange.xforce.ibmcloud.com/vulnerabilities/75563 https://github.com/horde/horde/commit/1228a6825a8dab3333d0a8c8986fc10d1f3d11b2

Share on: