from the 2.2.1 announcement: "This is a bugfix release that also fixes an XSS (cross site scripting) vulnerability in the contact view." http://secunia.com/advisories/30704/
I did not check if 2.1.7 is affected too, thus leaving the ranking at ?4 Could someone please check that and see if a fix is available in case it is affected as well.
Added horde-turba-2.2.1, removed vulnerable horde-turba-2.2 as it was unstable on all arches. webapps-done.
BTW, is there a plan to stabilize horde-* to the newer versions ?
CVE-2008-6746 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6746): Cross-site scripting (XSS) vulnerability in the contact display view in Turba Contact Manager H3 before 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the contact name.
(In reply to comment #1) > I did not check if 2.1.7 is affected too, thus leaving the ranking at ?4 > Could someone please check that and see if a fix is available in case it is > affected as well. > It is not. The vulnerable code is in contact.php which is not there in 2.1.7.