Show filters
194 Total Results
Displaying 61-70 of 194
Sort by:
Attacker Value
Unknown

CVE-2012-5567

Disclosure Date: April 05, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Horde Kronolith Calendar Application H4 before 3.0.18, as used in Horde Groupware Webmail Edition before 4.0.9, allow remote attackers to inject arbitrary web script or HTML via crafted event location parameters in the (1) month, (2) monthlist, or (3) prevmonthlist fields, related to portal blocks.
0
Attacker Value
Unknown

CVE-2012-5566

Disclosure Date: April 05, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Horde Kronolith Calendar Application H4 before 3.0.17, as used in Horde Groupware Webmail Edition before 4.0.8, allow remote attackers to inject arbitrary web script or HTML via the (1) tasks view or (2) search view.
0
Attacker Value
Unknown

CVE-2012-6640

Disclosure Date: April 05, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Horde Internet Mail Program (IMP) before 5.0.22, as used in Horde Groupware Webmail Edition before 4.0.9, allows remote attackers to inject arbitrary web script or HTML via a crafted SVG image attachment, a different vulnerability than CVE-2012-5565.
0
Attacker Value
Unknown

CVE-2012-5565

Disclosure Date: April 05, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in js/compose-dimp.js in Horde Internet Mail Program (IMP) before 5.0.24, as used in Horde Groupware Webmail Edition before 4.0.9, allows remote attackers to inject arbitrary web script or HTML via a crafted name for an attached file, related to the dynamic view.
0
Attacker Value
Unknown

CVE-2013-4714

Disclosure Date: November 06, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Tiki Wiki CMS Groupware 6 LTS before 6.13LTS, 9 LTS before 9.7LTS, 10.x before 10.4, and 11.x before 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-4715

Disclosure Date: November 06, 2013 (last updated October 05, 2023)
SQL injection vulnerability in Tiki Wiki CMS Groupware 6 LTS before 6.13LTS, 9 LTS before 9.7LTS, 10.x before 10.4, and 11.x before 11.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-2211

Disclosure Date: November 22, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in phpgwapi/inc/common_functions_inc.php in eGroupware before 1.8.004.20120405 allows remote attackers to inject arbitrary web script or HTML via the menuaction parameter to etemplate/process_exec.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2012-5321

Disclosure Date: October 08, 2012 (last updated October 05, 2023)
tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frames and conduct phishing attacks via the url parameter, aka "frame injection."
0
Attacker Value
Unknown

CVE-2011-4551

Disclosure Date: October 01, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in tiki-cookie-jar.php in TikiWiki CMS/Groupware before 8.2 and LTS before 6.5 allows remote attackers to inject arbitrary web script or HTML via arbitrary parameters.
0
Attacker Value
Unknown

CVE-2012-0209

Disclosure Date: September 25, 2012 (last updated October 05, 2023)
Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2012, contains an externally introduced modification (Trojan Horse) in templates/javascript/open_calendar.js, which allows remote attackers to execute arbitrary PHP code.
0