CVE-2008-6746
23.04.2009, 17:30
Cross-site scripting (XSS) vulnerability in the contact display view in Turba Contact Manager H3 before 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the contact name.
| Vendor | Product | Version |
|---|---|---|
| horde | turba_h3 | 𝑥 ≤ 2.2 |
| horde | turba_h3 | 0.0.1 |
| horde | turba_h3 | 0.0.2 |
| horde | turba_h3 | 0.0.3 |
| horde | turba_h3 | 1.0 |
| horde | turba_h3 | 1.0:rc4 |
| horde | turba_h3 | 1.1 |
| horde | turba_h3 | 1.2 |
| horde | turba_h3 | 1.2.1 |
| horde | turba_h3 | 1.2.2 |
| horde | turba_h3 | 1.2.3 |
| horde | turba_h3 | 1.2.4 |
| horde | turba_h3 | 1.2.5 |
| horde | turba_h3 | 2.0 |
| horde | turba_h3 | 2.0:alpha |
| horde | turba_h3 | 2.0:beta |
| horde | turba_h3 | 2.0:rc1 |
| horde | turba_h3 | 2.0:rc2 |
| horde | turba_h3 | 2.0:rc3 |
| horde | turba_h3 | 2.0.1 |
| horde | turba_h3 | 2.0.1:rc1 |
| horde | turba_h3 | 2.0.2 |
| horde | turba_h3 | 2.0.3 |
| horde | turba_h3 | 2.0.3:rc1 |
| horde | turba_h3 | 2.0.4 |
| horde | turba_h3 | 2.0.5 |
| horde | turba_h3 | 2.1 |
| horde | turba_h3 | 2.1:rc1 |
| horde | turba_h3 | 2.1.1 |
| horde | turba_h3 | 2.1.2 |
| horde | turba_h3 | 2.1.3 |
| horde | turba_h3 | 2.1.4 |
| horde | turba_h3 | 2.1.5 |
| horde | turba_h3 | 2.1.6 |
| horde | turba_h3 | 2.1.7 |
| horde | turba_h3 | 2.2:alpha |
| horde | turba_h3 | 2.2:rc1 |
| horde | turba_h3 | 2.2:rc2 |
| horde | turba_h3 | 2.2:rc3 |
| horde | turba_h3 | 2.2:rc4 |
𝑥
= Vulnerable software versions
References