CVE-2006-4255

Publication date 21 August 2006

Last updated 17 July 2025


Ubuntu priority

Description

Cross-site scripting (XSS) vulnerability in horde/imp/search.php in Horde IMP H3 before 4.1.3 allows remote attackers to include arbitrary web script or HTML via multiple unspecified vectors related to folder names, as injected into the vfolder_label form field in the IMP search screen.

Status

Package Ubuntu Release Status
imp4 9.10 karmic
Fixed 4.1.3-4
9.04 jaunty
Fixed 4.1.3-4
8.10 intrepid
Fixed 4.1.3-4
8.04 LTS hardy
Fixed 4.1.3-4
7.10 gutsy
Fixed 4.1.3-4
7.04 feisty
Fixed 4.1.3-4
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life


Access our resources on patching vulnerabilities