Vulnerability Description
Cross-site scripting (XSS) vulnerability in passwd/main.php in the Passwd module before 3.1.1 for Horde allows remote attackers to inject arbitrary web script or HTML via the backend parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Horde | Passwd | <= 3.1 |
Related Weaknesses (CWE)
References
- http://bugs.horde.org/ticket/8398
- http://lists.horde.org/archives/announce/2009/000507.htmlPatch
- http://secunia.com/advisories/35720Vendor Advisory
- http://secunia.com/advisories/35769
- http://www.debian.org/security/2009/dsa-1829
- http://www.securityfocus.com/bid/35573ExploitPatch
- http://www.vupen.com/english/advisories/2009/1784PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51542
- http://bugs.horde.org/ticket/8398
- http://lists.horde.org/archives/announce/2009/000507.htmlPatch
- http://secunia.com/advisories/35720Vendor Advisory
- http://secunia.com/advisories/35769
- http://www.debian.org/security/2009/dsa-1829
- http://www.securityfocus.com/bid/35573ExploitPatch
- http://www.vupen.com/english/advisories/2009/1784PatchVendor Advisory
FAQ
What is CVE-2009-2360?
CVE-2009-2360 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in passwd/main.php in the Passwd module before 3.1.1 for Horde allows remote attackers to inject arbitrary web script or HTML via the backend parameter.
How severe is CVE-2009-2360?
CVE-2009-2360 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-2360?
Check the references section above for vendor advisories and patch information. Affected products include: Horde Passwd.