Horde IMP HTML MIME Viewer Multiple XSS

medium Nessus Plugin ID 15393

Synopsis

The remote web server is running a PHP application that is affected by multiple cross-site scripting vulnerabilities.

Description

The target is running at least one instance of IMP whose version number is between 3.0 and 3.2.5 inclusive. Such versions are vulnerable to several cross-site scripting attacks when viewing HTML messages with the HTML MIME viewer and certain browsers.

***** Nessus has determined the vulnerability exists on the target
***** simply by looking at the version number of IMP installed there.

Solution

Upgrade to IMP version 3.2.6 or later.

See Also

https://lists.horde.org/archives/imp/Week-of-Mon-20040920/039246.html

Plugin Details

Severity: Medium

ID: 15393

File Name: imp_html_mime_viewer_xss.nasl

Version: 1.18

Type: remote

Published: 9/29/2004

Updated: 6/4/2024

Configuration: Enable thorough checks

Supported Sensors: Nessus

Enable CGI Scanning: true

Vulnerability Information

CPE: cpe:/a:horde:imp

Excluded KB Items: Settings/disable_cgi_scanning

Reference Information

CWE: 20, 442, 629, 711, 712, 722, 725, 74, 750, 751, 79, 800, 801, 809, 811, 864, 900, 928, 931, 990