Horde IMP HTML MIME Viewer Multiple XSS

This script is Copyright (C) 2003-2012 George A. Theall


Synopsis :

The remote web server is running a PHP application that is affected
by multiple cross-site scripting vulnerabilities.

Description :

The target is running at least one instance of IMP whose version
number is between 3.0 and 3.2.5 inclusive. Such versions are
vulnerable to several cross-site scripting attacks when viewing HTML
messages with the HTML MIME viewer and certain browsers.

***** Nessus has determined the vulnerability exists on the target
***** simply by looking at the version number of IMP installed there.

See also :

http://lists.horde.org/archives/imp/Week-of-Mon-20040920/039246.html

Solution :

Upgrade to IMP version 3.2.6 or later.

Risk factor :

Medium / CVSS Base Score : 4.3
(CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)

Family: CGI abuses : XSS

Nessus Plugin ID: 15393 (imp_html_mime_viewer_xss.nasl)

Bugtraq ID:

CVE ID: