CVE-2010-3695
Title: Horde Groupware Cross-Site Scripting (XSS)
XSS
Proof Of Concept
PoC Available for CVE-2010-3695
CWE Category
CWE-79
Published Date
Mar 31, 2011
Modified Date
Jun 16, 2026
Exploit Status
Available
Score
4.3
CVSS v2.0
Exploit Probability (EPSS)
4.98%
Vulnerability Summary
CVE-2010-3695: Cross-site scripting (XSS) vulnerability in fetchmailprefs.php in Horde IMP before 4.3.8, and Horde Groupware Webmail Edition before 1.2.7, allows remote attackers to inject arbitrary web script or HTML via the fm_id parameter in a fetchmail_prefs_save action, related to the Fetchmail configuration.
Impacted Vendors
Reference Links
http://archives.neohapsis.com/archives/fulldisclosure/2010-09/0379.html
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=598584
http://cvs.horde.org/diff.php/imp/docs/CHANGES?rt=horde&r1=1.699.2.424&r2=1.699.2.430&ty=h
http://git.horde.org/diff.php/groupware/docs/webmail/CHANGES?rt=horde&r1=1.35.2.11&r2=1.35.2.13&ty=h
http://git.horde.org/diff.php/imp/fetchmailprefs.php?rt=horde&r1=1.39.4.10&r2=1.39.4.11
http://lists.horde.org/archives/announce/2010/000558.html
http://lists.horde.org/archives/announce/2010/000568.html
http://openwall.com/lists/oss-security/2010/09/30/7
http://openwall.com/lists/oss-security/2010/09/30/8
http://openwall.com/lists/oss-security/2010/10/01/6
http://secunia.com/advisories/41627
http://secunia.com/advisories/43896
http://securityreason.com/securityalert/8170
http://www.debian.org/security/2011/dsa-2204
http://www.securityfocus.com/archive/1/513992/100/0/threaded
http://www.securityfocus.com/bid/43515
http://www.vupen.com/english/advisories/2010/2513
http://www.vupen.com/english/advisories/2011/0769
https://bugzilla.redhat.com/show_bug.cgi?id=641069
http://archives.neohapsis.com/archives/fulldisclosure/2010-09/0379.html
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=598584
http://cvs.horde.org/diff.php/imp/docs/CHANGES?rt=horde&r1=1.699.2.424&r2=1.699.2.430&ty=h
http://git.horde.org/diff.php/groupware/docs/webmail/CHANGES?rt=horde&r1=1.35.2.11&r2=1.35.2.13&ty=h
http://git.horde.org/diff.php/imp/fetchmailprefs.php?rt=horde&r1=1.39.4.10&r2=1.39.4.11
http://lists.horde.org/archives/announce/2010/000558.html
http://lists.horde.org/archives/announce/2010/000568.html
http://openwall.com/lists/oss-security/2010/09/30/7
http://openwall.com/lists/oss-security/2010/09/30/8
http://openwall.com/lists/oss-security/2010/10/01/6
http://secunia.com/advisories/41627
http://secunia.com/advisories/43896
http://securityreason.com/securityalert/8170
http://www.debian.org/security/2011/dsa-2204
http://www.securityfocus.com/archive/1/513992/100/0/threaded
http://www.securityfocus.com/bid/43515
http://www.vupen.com/english/advisories/2010/2513
http://www.vupen.com/english/advisories/2011/0769
https://bugzilla.redhat.com/show_bug.cgi?id=641069
CVSS v2.0
Source Entity
[email protected]
Severity
MEDIUM
4.3
Access Vector
N/A
Authentication
N/A
RAW VECTOR
AV:N/AC:M/Au:N/C:N/I:P/A:N
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2010-3695 Exploits & PoCs (Proof Of Concept)
Exploit-DB
https://www.exploit-db.com/exploits/34773
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
N/A
Complexity
N/A
Privileges
N/A
Interaction
NONE
CVSS Vector String
AV:N/AC:M/Au:N/C:N/I:P/A:N
Affected Stack
No specific products linked.