Show filters
42 Total Results
Displaying 31-40 of 42
Sort by:
Attacker Value
Unknown
CVE-2006-2195
Disclosure Date: June 15, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in horde 3 (horde3) before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via (1) templates/problem/problem.inc and (2) test.php.
0
Attacker Value
Unknown
CVE-2006-1496
Disclosure Date: March 30, 2006 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in index.php in ViHor Design allow remote attackers to inject arbitrary web script or HTML via (1) a remote URL in the page parameter, which is processed by an fopen call, or (2) HTML or script in the page parameter, which is returned to the client in an error message for the failed fopen call.
0
Attacker Value
Unknown
CVE-2006-1497
Disclosure Date: March 30, 2006 (last updated February 22, 2025)
Directory traversal vulnerability in index.php in ViHor Design allows remote attackers to read arbitrary files via the page parameter.
0
Attacker Value
Unknown
CVE-2006-1260
Disclosure Date: March 19, 2006 (last updated February 22, 2025)
Horde Application Framework 3.0.9 allows remote attackers to read arbitrary files via a null character in the url parameter in services/go.php, which bypasses a sanity check.
0
Attacker Value
Unknown
CVE-2005-4190
Disclosure Date: December 13, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Horde Application Framework before 3.0.8 allow remote authenticated users to inject arbitrary web script or HTML via multiple vectors, as demonstrated by (1) the identity field, (2) Category and (3) Label search fields, (4) the Mobile Phone field, and (5) Date and (6) Time fields when importing CSV files, as exploited through modules such as (a) Turba Address Book, (b) Kronolith, (c) Mnemo, and (d) Nag.
0
Attacker Value
Unknown
CVE-2005-3759
Disclosure Date: November 22, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Horde before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) gzip/tar and (2) css MIME viewers, which do not filter or escape dangerous HTML when extracting and displaying attachments.
0
Attacker Value
Unknown
CVE-2005-3344
Disclosure Date: November 16, 2005 (last updated February 22, 2025)
The default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain access.
0
Attacker Value
Unknown
CVE-2005-3570
Disclosure Date: November 16, 2005 (last updated February 22, 2025)
Unspecified cross-site scripting (XSS) vulnerability in Horde before 2.2.9 allows remote attackers to inject arbitrary web script or HTML via "not properly escaped error messages".
0
Attacker Value
Unknown
CVE-2005-0378
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Horde 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to prefs.php or (2) url parameter to index.php.
0
Attacker Value
Unknown
CVE-2003-0728
Disclosure Date: October 20, 2003 (last updated February 22, 2025)
Horde before 2.2.4 allows remote malicious web sites to steal session IDs and read or create arbitrary email by stealing the ID from a referrer URL.
0