Vulnerabilities > Horde

DATE CVE VULNERABILITY TITLE RISK
2006-10-23 CVE-2006-5449 Unspecified vulnerability in Horde Ingo H3
procmail in Ingo H3 before 1.1.2 Horde module allows remote authenticated users to execute arbitrary commands via shell metacharacters in the mailbox destination of a filter rule.
network
low complexity
horde
6.5
2006-08-21 CVE-2006-4256 Cross-Site Scripting vulnerability in Application Framework
index.php in Horde Application Framework before 3.1.2 allows remote attackers to include web pages from other sites, which could be useful for phishing attacks, via a URL in the url parameter, aka "cross-site referencing." NOTE: some sources have referred to this issue as XSS, but it is different than classic XSS.
network
horde
4.3
2006-08-21 CVE-2006-4255 Cross-Site Scripting vulnerability in Horde Products Search.PHP
Cross-site scripting (XSS) vulnerability in horde/imp/search.php in Horde IMP H3 before 4.1.3 allows remote attackers to include arbitrary web script or HTML via multiple unspecified vectors related to folder names, as injected into the vfolder_label form field in the IMP search screen.
network
horde
4.3
2006-07-13 CVE-2006-3549 Cross-Site Scripting vulnerability in Horde Application Framework Services
services/go.php in Horde Application Framework 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1 does not properly restrict its image proxy capability, which allows remote attackers to perform "Web tunneling" attacks and use the server as a proxy via (1) http, (2) https, and (3) ftp URL in the url parameter, which is requested from the server.
network
low complexity
horde
5.0
2006-07-13 CVE-2006-3548 Cross-Site Scripting vulnerability in Horde Application Framework Services
Multiple cross-site scripting (XSS) vulnerabilities in Horde Application Framework 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1 allow remote attackers to inject arbitrary web script or HTML via a (1) javascript URI or an external (2) http, (3) https, or (4) ftp URI in the url parameter in services/go.php (aka the dereferrer), (5) a javascript URI in the module parameter in services/help (aka the help viewer), and (6) the name parameter in services/problem.php (aka the problem reporting screen).
network
horde
4.3
2006-06-15 CVE-2006-2195 Cross-Site Scripting vulnerability in Horde Application Framework
Cross-site scripting (XSS) vulnerability in horde 3 (horde3) before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via (1) templates/problem/problem.inc and (2) test.php.
network
horde
6.8
2006-03-29 CVE-2006-1491 Code Injection vulnerability in Horde Application Framework
Eval injection vulnerability in Horde Application Framework versions 3.0 before 3.0.10 and 3.1 before 3.1.1 allows remote attackers to execute arbitrary code via the help viewer.
network
low complexity
horde CWE-94
7.5
2006-03-19 CVE-2006-1260 Information Disclosure vulnerability in Horde Application Framework
Horde Application Framework 3.0.9 allows remote attackers to read arbitrary files via a null character in the url parameter in services/go.php, which bypasses a sanity check.
network
low complexity
horde
5.0
2005-12-14 CVE-2005-4242 Cross-Site Scripting vulnerability in Turba H3
Multiple cross-site scripting (XSS) vulnerabilities in Horde Turba H3 2.0.4 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the address book and (2) contact data.
network
horde
4.3
2005-12-13 CVE-2005-4192 Remote HTML Injection vulnerability in Horde Mnemo
Multiple cross-site scripting (XSS) vulnerabilities in templates/notepads/notepads.inc in Horde Mnemo Note Manager H3 before 2.0.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) the notepad's name or (2) description, when creating a new notepad.
network
horde
3.5