| Summary | Cross Site Scripting Vulnerability |
| Queue | Passwd |
| Queue Version | 3.1 |
| Type | Bug |
| State | Resolved |
| Priority | 2. Medium |
| Owners | chuck (at) horde (dot) org |
| Requester | security (at) davidwharton (dot) us |
| Created | 07/03/2009 (5971 days ago) |
| Due | |
| Updated | 07/05/2009 (5969 days ago) |
| Assigned | |
| Resolved | 07/05/2009 (5969 days ago) |
| Github Issue Link | |
| Github Pull Request | |
| Milestone | |
| Patch | No |
Assigned to Chuck Hagenbuch
State ⇒ Resolved
http://cvs.horde.org/diff.php/passwd/docs/CHANGES?rt=horde&r1=1.110&r2=1.111&ty=u
http://cvs.horde.org/diff.php/passwd/main.php?rt=horde&r1=1.82&r2=1.83&ty=u
http://cvs.horde.org/diff.php/passwd/templates/main/main.inc?rt=horde&r1=1.41&r2=1.42&ty=u
Priority ⇒ 2. Medium
Patch ⇒ No
Milestone ⇒
Queue ⇒ Passwd
Summary ⇒ Cross Site Scripting Vulnerability
Type ⇒ Bug
State ⇒ Unconfirmed
http://hordeserver.com/horde/passwd/main.php?backend="><!--a75c305b1c0a6022--><script>alert('XSS')</script>&userid=stevejobs&return_to=&oldpassword=foo&newpassword0=foo&newpassword1=foo&submit=Change%20Password