Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2005-4080

Опубликовано: 08 дек. 2005
Источник: debian
EPSS Низкий

Описание

Horde IMP 4.0.4 and earlier does not sanitize strings containing UTF16 null characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via UTF16 encoded attachments and strings that will be executed when viewed using Internet Explorer, which ignores the characters.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
imp4fixed4.0.4-1package

Примечания

  • Internet Explorer bug, most definitely fixed since long, didn't check though

EPSS

Процентиль: 77%
0.01047
Низкий

Связанные уязвимости

nvd
почти 20 лет назад

Horde IMP 4.0.4 and earlier does not sanitize strings containing UTF16 null characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via UTF16 encoded attachments and strings that will be executed when viewed using Internet Explorer, which ignores the characters.

github
больше 3 лет назад

Horde IMP 4.0.4 and earlier does not sanitize strings containing UTF16 null characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via UTF16 encoded attachments and strings that will be executed when viewed using Internet Explorer, which ignores the characters.

EPSS

Процентиль: 77%
0.01047
Низкий