VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : 脆弱性脅威分析用情報の定型データ配信
[ about VRDA Feed | JPCERT/CC



 
分析対象脆弱性情報 (リビジョン番号 : 1) [ Download XML
CVE-2012-0909
groupware_webmail_edition: Cross-site scripting (XSS) vulnerability in Horde_F...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0909

原文

Cross-site scripting (XSS) vulnerability in Horde_Form in Horde Groupware Webmail Edition before 4.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to email verification. NOTE: Some of these details are obtained from third party information.

翻訳   (表示)





この情報について
分析情報提供元:
NIST NVD
初版公開日:
2012-01-24
分析対象脆弱性情報の分類:
アドバイザリ・注意喚起
最終更新日:
2012-01-25




脆弱性の影響を受ける製品の識別子
cpe/search/results?searchChoice=name&amp;searchText=cpe%3A%2Fa%3Ahorde%3Agroupware_webmail_edition%3A4.0.5&amp;includeDeprecated=true&amp;page_num=0&amp;cid=1" title="cpe:/a:horde:groupware_webmail_edition:4.0.5" id="j_id241:0:0:0:0:j_id248" target="_blank">cpe:/a:horde:groupware_webmail_edition:4.0.5</a> and previous versions
 


脆弱性の分析内容
[攻撃元区分]  [?]
未評価 [?]

ローカル [?]
隣接 [?]
X ネットワーク [?]

[攻撃条件の複雑さ]  [?]
未評価 [?]

 [?]
X [?]
 [?]

[攻撃前の認証要否]  [?]
未評価 [?]

複数 [?]
単一 [?]
X 不要 [?]

[機密性への影響]  [?]
未評価 [?]

X 影響なし [?]
部分的 [?]
全面的 [?]

[完全性への影響]  [?]
未評価 [?]

影響なし [?]
X 部分的 [?]
全面的 [?]

[可用性への影響]  [?]
未評価 [?]

X 影響なし [?]
部分的 [?]
全面的 [?]

関連情報




参考情報
BID 51586




CONFIRM http://www.horde.org/apps/webmail/docs/RELEASE_NOTES




CONFIRM http://www.horde.org/apps/webmail/docs/CHANGES




MLIST [oss-security] 20120121 Re: Re: CVE Request -- Horde IMP -- Multiple XSS flaws




SECUNIA 47592




Vulnerability Type Cross-Site Scripting (XSS) (CWE-79)





Copyright © 2012 JPCERT/CC All Rights Reserved.