CVE
- Id
- 15284
- CVE No.
- CVE-2005-4080
- Status
- Candidate
- Description
- Horde IMP 4.0.4 and earlier does not sanitize strings containing UTF16 null characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via UTF16 encoded attachments and strings that will be executed when viewed using Internet Explorer, which ignores the characters.
- Phase
- Assigned (20051208)
- Votes
- None (candidate not yet proposed)
- Comments