Horde

Horde

18 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 64.77%
  • Published 25.09.2012 22:55:00
  • Last modified 11.04.2025 00:51:21

Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2012, contains an externally introduced modification (Trojan Horse) in templates/javascript/open_calendar.js, w...

  • EPSS 0.21%
  • Published 22.06.2010 17:30:01
  • Last modified 11.04.2025 00:51:21

The IMP plugin in Horde allows remote attackers to bypass firewall restrictions and use Horde as a proxy to scan internal networks via a crafted request to an unspecified test script. NOTE: this is only a vulnerability when the administrator does no...

  • EPSS 1.85%
  • Published 13.09.2009 22:30:00
  • Last modified 09.04.2025 00:30:58

Unspecified vulnerability in the Horde API in Horde 3.1 before 3.1.6 and 3.2 before 3.2 before 3.2-RC2; Turba H3 2.1 before 2.1.6 and 2.2 before 2.2-RC2; Kronolith H3 2.1 before 2.1.7 and H3 2.2 before 2.2-RC2; Nag H3 2.1 before 2.1.4 and 2.2 before ...

Exploit
  • EPSS 0.75%
  • Published 12.09.2008 16:56:20
  • Last modified 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in (1) Text_Filter/Filter/xss.php in Horde 3.1.x before 3.1.9 and 3.2.x before 3.2.2 and (2) externalinput.php in Popoon r22196 and earlier allows remote attackers to inject arbitrary web script or HTML by usi...

Exploit
  • EPSS 0.6%
  • Published 12.09.2008 16:56:20
  • Last modified 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in MIME/MIME/Contents.php in the MIME library in Horde 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via the filename of a MIME attachment in an e-mail message.

  • EPSS 1.31%
  • Published 11.03.2008 00:44:00
  • Last modified 09.04.2025 00:30:58

Directory traversal vulnerability in Horde 3.1.6, Groupware before 1.0.5, and Groupware Webmail Edition before 1.0.6, when running with certain configurations, allows remote authenticated users to read and execute arbitrary files via ".." sequences a...

  • EPSS 1.15%
  • Published 11.01.2008 02:46:00
  • Last modified 09.04.2025 00:30:58

IMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3 does not validate unspecified HTTP requests, which allows remote attackers to (1) delete arbitrary e-mail messages via a modified numeric ID or (2)...

  • EPSS 0.8%
  • Published 21.08.2006 20:04:00
  • Last modified 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in horde/imp/search.php in Horde IMP H3 before 4.1.3 allows remote attackers to include arbitrary web script or HTML via multiple unspecified vectors related to folder names, as injected into the vfolder_label...

Exploit
  • EPSS 1.14%
  • Published 13.07.2006 00:05:00
  • Last modified 03.04.2025 01:03:51

Multiple cross-site scripting (XSS) vulnerabilities in Horde Application Framework 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1 allow remote attackers to inject arbitrary web script or HTML via a (1) javascript URI or an external (2) http, (3) https,...

  • EPSS 4.37%
  • Published 15.06.2006 10:02:00
  • Last modified 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in horde 3 (horde3) before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via (1) templates/problem/problem.inc and (2) test.php.