- EPSS 25.72%
- Published 19.03.2006 02:02:00
- Last modified 03.04.2025 01:03:51
Horde Application Framework 3.0.9 allows remote attackers to read arbitrary files via a null character in the url parameter in services/go.php, which bypasses a sanity check.
CVE-2005-3759
- EPSS 0.71%
- Published 22.11.2005 21:03:00
- Last modified 03.04.2025 01:03:51
Multiple cross-site scripting (XSS) vulnerabilities in Horde before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) gzip/tar and (2) css MIME viewers, which do not filter or escape dangerous HTML when extracting and di...
CVE-2005-3570
- EPSS 1.32%
- Published 16.11.2005 07:42:00
- Last modified 03.04.2025 01:03:51
Unspecified cross-site scripting (XSS) vulnerability in Horde before 2.2.9 allows remote attackers to inject arbitrary web script or HTML via "not properly escaped error messages".
- EPSS 10.15%
- Published 16.11.2005 07:42:00
- Last modified 03.04.2025 01:03:51
The default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain access.
CVE-2005-0378
- EPSS 0.5%
- Published 02.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Multiple cross-site scripting (XSS) vulnerabilities in Horde 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to prefs.php or (2) url parameter to index.php.
CVE-2003-0728
- EPSS 0.59%
- Published 20.10.2003 04:00:00
- Last modified 03.04.2025 01:03:51
Horde before 2.2.4 allows remote malicious web sites to steal session IDs and read or create arbitrary email by stealing the ID from a referrer URL.
CVE-2002-0181
- EPSS 1.5%
- Published 22.04.2002 04:00:00
- Last modified 03.04.2025 01:03:51
Cross-site scripting vulnerability in status.php3 for IMP 2.2.8 and HORDE 1.2.7 allows remote attackers to execute arbitrary web script and steal cookies of other IMP/HORDE users via the script parameter.
CVE-2000-0910
- EPSS 0.1%
- Published 19.12.2000 05:00:00
- Last modified 03.04.2025 01:03:51
Horde library 1.02 allows attackers to execute arbitrary commands via shell metacharacters in the "from" address.