Show filters
42 Total Results
Displaying 31-40 of 42
Sort by:
Attacker Value
Unknown

CVE-2006-2195

Disclosure Date: June 15, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in horde 3 (horde3) before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via (1) templates/problem/problem.inc and (2) test.php.
0
Attacker Value
Unknown

CVE-2006-1496

Disclosure Date: March 30, 2006 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in index.php in ViHor Design allow remote attackers to inject arbitrary web script or HTML via (1) a remote URL in the page parameter, which is processed by an fopen call, or (2) HTML or script in the page parameter, which is returned to the client in an error message for the failed fopen call.
0
Attacker Value
Unknown

CVE-2006-1497

Disclosure Date: March 30, 2006 (last updated February 22, 2025)
Directory traversal vulnerability in index.php in ViHor Design allows remote attackers to read arbitrary files via the page parameter.
0
Attacker Value
Unknown

CVE-2006-1260

Disclosure Date: March 19, 2006 (last updated February 22, 2025)
Horde Application Framework 3.0.9 allows remote attackers to read arbitrary files via a null character in the url parameter in services/go.php, which bypasses a sanity check.
0
Attacker Value
Unknown

CVE-2005-4190

Disclosure Date: December 13, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Horde Application Framework before 3.0.8 allow remote authenticated users to inject arbitrary web script or HTML via multiple vectors, as demonstrated by (1) the identity field, (2) Category and (3) Label search fields, (4) the Mobile Phone field, and (5) Date and (6) Time fields when importing CSV files, as exploited through modules such as (a) Turba Address Book, (b) Kronolith, (c) Mnemo, and (d) Nag.
0
Attacker Value
Unknown

CVE-2005-3759

Disclosure Date: November 22, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Horde before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) gzip/tar and (2) css MIME viewers, which do not filter or escape dangerous HTML when extracting and displaying attachments.
0
Attacker Value
Unknown

CVE-2005-3344

Disclosure Date: November 16, 2005 (last updated February 22, 2025)
The default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain access.
0
Attacker Value
Unknown

CVE-2005-3570

Disclosure Date: November 16, 2005 (last updated February 22, 2025)
Unspecified cross-site scripting (XSS) vulnerability in Horde before 2.2.9 allows remote attackers to inject arbitrary web script or HTML via "not properly escaped error messages".
0
Attacker Value
Unknown

CVE-2005-0378

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Horde 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to prefs.php or (2) url parameter to index.php.
0
Attacker Value
Unknown

CVE-2003-0728

Disclosure Date: October 20, 2003 (last updated February 22, 2025)
Horde before 2.2.4 allows remote malicious web sites to steal session IDs and read or create arbitrary email by stealing the ID from a referrer URL.
0