6.8
CVE-2010-3694
- EPSS 0.17%
- Published 09.11.2010 21:00:04
- Last modified 11.04.2025 00:51:21
- Source secalert@redhat.com
- Teams watchlist Login
- Open Login
Cross-site request forgery (CSRF) vulnerability in the Horde Application Framework before 3.3.9 allows remote attackers to hijack the authentication of unspecified victims for requests to a preference form.
Data is provided by the National Vulnerability Database (NVD)
Horde ≫ Horde Application Framework Version <= 3.3.8
Horde ≫ Horde Application Framework Version1.0.3
Horde ≫ Horde Application Framework Version1.1.1
Horde ≫ Horde Application Framework Version1.3.0
Horde ≫ Horde Application Framework Version1.3.1
Horde ≫ Horde Application Framework Version1.3.2
Horde ≫ Horde Application Framework Version1.3.3
Horde ≫ Horde Application Framework Version1.3.4
Horde ≫ Horde Application Framework Version1.3.5
Horde ≫ Horde Application Framework Version2.0
Horde ≫ Horde Application Framework Version2.0 Updaterc1
Horde ≫ Horde Application Framework Version2.0 Updaterc3
Horde ≫ Horde Application Framework Version2.0 Updaterc4
Horde ≫ Horde Application Framework Version2.1
Horde ≫ Horde Application Framework Version2.2
Horde ≫ Horde Application Framework Version2.2.1
Horde ≫ Horde Application Framework Version2.2.2
Horde ≫ Horde Application Framework Version2.2.3
Horde ≫ Horde Application Framework Version2.2.4
Horde ≫ Horde Application Framework Version2.2.5
Horde ≫ Horde Application Framework Version2.2.6
Horde ≫ Horde Application Framework Version2.2.6 Updaterc1
Horde ≫ Horde Application Framework Version2.2.7
Horde ≫ Horde Application Framework Version2.2.8
Horde ≫ Horde Application Framework Version2.2.9
Horde ≫ Horde Application Framework Version3.0
Horde ≫ Horde Application Framework Version3.0 Updatealpha
Horde ≫ Horde Application Framework Version3.0 Updatebeta
Horde ≫ Horde Application Framework Version3.0 Updaterc1
Horde ≫ Horde Application Framework Version3.0 Updaterc2
Horde ≫ Horde Application Framework Version3.0 Updaterc3
Horde ≫ Horde Application Framework Version3.0.1
Horde ≫ Horde Application Framework Version3.0.2
Horde ≫ Horde Application Framework Version3.0.3
Horde ≫ Horde Application Framework Version3.0.3 Updaterc1
Horde ≫ Horde Application Framework Version3.0.4
Horde ≫ Horde Application Framework Version3.0.4 Updaterc1
Horde ≫ Horde Application Framework Version3.0.4 Updaterc2
Horde ≫ Horde Application Framework Version3.0.5
Horde ≫ Horde Application Framework Version3.0.5 Updaterc1
Horde ≫ Horde Application Framework Version3.0.5 Updaterc2
Horde ≫ Horde Application Framework Version3.0.6
Horde ≫ Horde Application Framework Version3.0.6 Updaterc1
Horde ≫ Horde Application Framework Version3.0.7
Horde ≫ Horde Application Framework Version3.0.8
Horde ≫ Horde Application Framework Version3.0.9
Horde ≫ Horde Application Framework Version3.0.10
Horde ≫ Horde Application Framework Version3.0.11
Horde ≫ Horde Application Framework Version3.0.12
Horde ≫ Horde Application Framework Version3.1
Horde ≫ Horde Application Framework Version3.1 Updaterc1
Horde ≫ Horde Application Framework Version3.1 Updaterc2
Horde ≫ Horde Application Framework Version3.1 Updaterc3
Horde ≫ Horde Application Framework Version3.1.1
Horde ≫ Horde Application Framework Version3.1.2
Horde ≫ Horde Application Framework Version3.1.3
Horde ≫ Horde Application Framework Version3.1.4
Horde ≫ Horde Application Framework Version3.1.4 Updaterc1
Horde ≫ Horde Application Framework Version3.1.5
Horde ≫ Horde Application Framework Version3.1.6
Horde ≫ Horde Application Framework Version3.1.7
Horde ≫ Horde Application Framework Version3.1.8
Horde ≫ Horde Application Framework Version3.1.9
Horde ≫ Horde Application Framework Version3.2
Horde ≫ Horde Application Framework Version3.2 Updatealpha
Horde ≫ Horde Application Framework Version3.2 Updaterc1
Horde ≫ Horde Application Framework Version3.2 Updaterc2
Horde ≫ Horde Application Framework Version3.2 Updaterc3
Horde ≫ Horde Application Framework Version3.2 Updaterc4
Horde ≫ Horde Application Framework Version3.2.1
Horde ≫ Horde Application Framework Version3.2.2
Horde ≫ Horde Application Framework Version3.2.3
Horde ≫ Horde Application Framework Version3.2.4
Horde ≫ Horde Application Framework Version3.2.5
Horde ≫ Horde Application Framework Version3.3
Horde ≫ Horde Application Framework Version3.3 Updaterc1
Horde ≫ Horde Application Framework Version3.3.1
Horde ≫ Horde Application Framework Version3.3.2
Horde ≫ Horde Application Framework Version3.3.3
Horde ≫ Horde Application Framework Version3.3.4
Horde ≫ Horde Application Framework Version3.3.4 Updaterc1
Horde ≫ Horde Application Framework Version3.3.5
Horde ≫ Horde Application Framework Version3.3.6
Horde ≫ Horde Application Framework Version3.3.7
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.17% | 0.355 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.