Show filters
15 Total Results
Displaying 11-15 of 15
Sort by:
Attacker Value
Unknown

CVE-2006-1260

Disclosure Date: March 19, 2006 (last updated February 22, 2025)
Horde Application Framework 3.0.9 allows remote attackers to read arbitrary files via a null character in the url parameter in services/go.php, which bypasses a sanity check.
0
Attacker Value
Unknown

CVE-2005-4190

Disclosure Date: December 13, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Horde Application Framework before 3.0.8 allow remote authenticated users to inject arbitrary web script or HTML via multiple vectors, as demonstrated by (1) the identity field, (2) Category and (3) Label search fields, (4) the Mobile Phone field, and (5) Date and (6) Time fields when importing CSV files, as exploited through modules such as (a) Turba Address Book, (b) Kronolith, (c) Mnemo, and (d) Nag.
0
Attacker Value
Unknown

CVE-2005-3759

Disclosure Date: November 22, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Horde before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) gzip/tar and (2) css MIME viewers, which do not filter or escape dangerous HTML when extracting and displaying attachments.
0
Attacker Value
Unknown

CVE-2005-3570

Disclosure Date: November 16, 2005 (last updated February 22, 2025)
Unspecified cross-site scripting (XSS) vulnerability in Horde before 2.2.9 allows remote attackers to inject arbitrary web script or HTML via "not properly escaped error messages".
0
Attacker Value
Unknown

CVE-2002-0181

Disclosure Date: April 22, 2002 (last updated February 22, 2025)
Cross-site scripting vulnerability in status.php3 for IMP 2.2.8 and HORDE 1.2.7 allows remote attackers to execute arbitrary web script and steal cookies of other IMP/HORDE users via the script parameter.
0