CVE-2008-3823
Cross-site scripting (XSS) vulnerability in MIME/MIME/Contents.php in the MIME library in Horde 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via the filename of a MIME attachment in an e-mail message.
Date published : 2008-09-12
http://www.securityfocus.com/bid/31110
http://www.securityfocus.com/archive/1/496182/100/0/threaded