Horde Gollem 1.0.2 Release Candidate 1

CPE Details

Horde Gollem 1.0.2 Release Candidate 1
1.0.2
2011-04-04
10h43 +00:00
2011-05-25
15h36 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:horde:gollem:1.0.2:rc1:*:*:*:*:*:*

Informations

Vendor

horde

Product

gollem

Version

1.0.2

Update

rc1

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2020-8034 2020-05-18 14h07 +00:00 Gollem before 3.0.13, as used in Horde Groupware Webmail Edition 5.2.22 and other products, is affected by a reflected Cross-Site Scripting (XSS) vulnerability via the HTTP GET dir parameter in the browser functionality, affecting breadcrumb output. An attacker can obtain access to a victim's webmail account by making them visit a malicious URL.
6.1
Moyen
CVE-2010-3447 2011-04-01 19h00 +00:00 Cross-site scripting (XSS) vulnerability in view.php in the file viewer in Horde Gollem before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the file parameter in a view_file action.
4.3