---
title: "CVE-2005-4191\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2005-4191?format=md
keywords: index, follow
---

# CVE-2005-4191

Publication date 13 December 2005

Last updated 17 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Multiple cross-site scripting (XSS) vulnerabilities in
templates/tasklists/tasklists.inc in Horde Nag Task List Manager H3 before
2.0.4 allow remote authenticated users to inject arbitrary web script or
HTML via (1) the tasklist's name or (2) description, when creating a new
tasklist.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| nag2 | 7.04 feisty | Fixed 2.0.4-1 |
| 6.10 edgy | Fixed 2.0.4-1 |
| 6.06 LTS dapper | Fixed 2.0.4-1 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4191)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2005-4191)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2005-4191)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2005-4191)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2005-4191>
