CVE-2007-1679

Publication date 26 March 2007

Last updated 4 August 2025


Ubuntu priority

Negligible

Why this priority?

Cvss 3 Severity Score

5.4 · Medium

Score breakdown

Description

Multiple cross-site scripting (XSS) vulnerabilities in Horde Groupware Webmail 1.0 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors in (1) imp/search.php and (2) ingo/rule.php. NOTE: this issue has been disputed by the vendor, noting that the search.php issue was resolved in CVE-2006-4255, and attackers can only use rule.php to inject XSS into their own pages

Read the notes from the security team

Status

Package Ubuntu Release Status
horde3 9.04 jaunty Ignored end of life, was needed
8.10 intrepid Ignored end of life, was needed
8.04 LTS hardy Ignored end of life, was needed
7.10 gutsy Ignored end of life, was needed
7.04 feisty Ignored end of life, was needed
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life, was needed

Notes


jdstrand

Allegedly a duplicate of CVE-2006-4255.

Severity score breakdown

Parameter Value
Base score 5.4 · Medium
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Scope Changed
Confidentiality Low
Integrity impact Low
Availability impact None
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Access our resources on patching vulnerabilities