- EPSS 25.72%
- Veröffentlicht 19.03.2006 02:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Horde Application Framework 3.0.9 allows remote attackers to read arbitrary files via a null character in the url parameter in services/go.php, which bypasses a sanity check.
CVE-2005-3759
- EPSS 0.71%
- Veröffentlicht 22.11.2005 21:03:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple cross-site scripting (XSS) vulnerabilities in Horde before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) gzip/tar and (2) css MIME viewers, which do not filter or escape dangerous HTML when extracting and di...
CVE-2005-3570
- EPSS 1.32%
- Veröffentlicht 16.11.2005 07:42:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Unspecified cross-site scripting (XSS) vulnerability in Horde before 2.2.9 allows remote attackers to inject arbitrary web script or HTML via "not properly escaped error messages".
- EPSS 10.15%
- Veröffentlicht 16.11.2005 07:42:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain access.
CVE-2005-0378
- EPSS 0.5%
- Veröffentlicht 02.05.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple cross-site scripting (XSS) vulnerabilities in Horde 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to prefs.php or (2) url parameter to index.php.
CVE-2003-0728
- EPSS 0.59%
- Veröffentlicht 20.10.2003 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Horde before 2.2.4 allows remote malicious web sites to steal session IDs and read or create arbitrary email by stealing the ID from a referrer URL.
CVE-2002-0181
- EPSS 1.5%
- Veröffentlicht 22.04.2002 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Cross-site scripting vulnerability in status.php3 for IMP 2.2.8 and HORDE 1.2.7 allows remote attackers to execute arbitrary web script and steal cookies of other IMP/HORDE users via the script parameter.
CVE-2000-0910
- EPSS 0.1%
- Veröffentlicht 19.12.2000 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Horde library 1.02 allows attackers to execute arbitrary commands via shell metacharacters in the "from" address.