Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2010-3694
Disclosure Date: November 09, 2010 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in the Horde Application Framework before 3.3.9 allows remote attackers to hijack the authentication of unspecified victims for requests to a preference form.
0
Attacker Value
Unknown
CVE-2010-3077
Disclosure Date: November 09, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in util/icon_browser.php in the Horde Application Framework before 3.3.9 allows remote attackers to inject arbitrary web script or HTML via the subdir parameter.
0
Attacker Value
Unknown
CVE-2007-1473
Disclosure Date: March 16, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in framework/NLS/NLS.php in Horde Framework before 3.1.4 RC1, when the login page contains a language selection box, allows remote attackers to inject arbitrary web script or HTML via the new_lang parameter to login.php.
0
Attacker Value
Unknown
CVE-2007-1474
Disclosure Date: March 16, 2007 (last updated October 04, 2023)
Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows local users to delete arbitrary files and possibly gain privileges via multiple space-delimited pathnames.
0