CVE-2005-0378

Publication date 2 May 2005

Last updated 17 July 2025


Ubuntu priority

Description

Multiple cross-site scripting (XSS) vulnerabilities in Horde 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to prefs.php or (2) url parameter to index.php.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
horde2 7.04 feisty Not in release
6.10 edgy
Fixed 2.2.9-1
6.06 LTS dapper
Fixed 2.2.9-1