CVE-2008-4182 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4182): Cross-site scripting (XSS) vulnerability in imp/test.php in Horde Turba Contact Manager H3 2.2.1, and possibly other Horde Project products, allows remote attackers to inject arbitrary web script or HTML via the User field in an IMAP session.
The test.php scripts are automatically handled with "chmod 000" within the horde.eclass. These scripts are not meant to be used by the outside world as they provide detailed server information so they are locked down by default. Opening this hole requires the user to actively change permissions on these files. I consider this irrelevant. Objections?
(In reply to comment #1) > Objections? No.