← Back

CVE-2014-4946

nvd nist
Published: Jul 14, 2014Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in Horde Internet Mail Program (IMP) before 6.1.8, as used in Horde Groupware Webmail Edition before 5.1.5, allow remote attackers to inject arbitrary web script or HTML via (1) unspecified flags or (2) a mailbox name in the dynamic mailbox view.

Affected (37)

2 products
Groupware
Internet Mail Program
Configuration A
37 vulnerable
Vulnerable SoftwareAffected Versions
Horde
Up to 5.1.4
Version 5.0.0
Version 5.0.0 rc1
Version 5.0.1
Version 5.0.2
Version 5.0.3
Version 5.0.4
Version 5.0.5
Version 5.1.0
Version 5.1.0 rc1
Version 5.1.1
Version 5.1.2
Version 5.1.3
Horde
Up to 6.1.7
Version 6.0.0
Version 6.0.0 alpha1
Version 6.0.0 beta1
Version 6.0.0 beta2
Version 6.0.0 beta3
Version 6.0.0 beta4
Version 6.0.0 rc1
Version 6.0.1
Version 6.0.2
Version 6.0.3
Version 6.0.4
Version 6.0.5
Version 6.0.6
Version 6.1.0
Version 6.1.0 beta1
Version 6.1.0 beta2
Version 6.1.0 rc1
Version 6.1.1
Version 6.1.2
Version 6.1.3
Version 6.1.4
Version 6.1.5
Version 6.1.6

Timeline

No history available yet.