Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
horde horde application framework vulnerabilities and exploits
(subscribe to this query)
NA
CVE_2022_40684
Official Writeup - Simple CTF 2.0 Created: April 23, 2024 7:50 PM Today I completed an other room on TryHackMe with a simple file-upload vulnerability which I built. I have tried for dancing around this whole CTF machine and getting a lot of walls of challenges in the end it co...
1 Github repository
6.5
CVSSv2
CVE-2019-9858
Remote code execution exists in Horde Groupware Webmail 5.2.22 and 5.2.17. Horde/Form/Type.php contains a vulnerable class that handles image upload in forms. When the Horde_Form_Type_image method onSubmit() is called on uploads, it invokes the functions getImage() and _getUpload...
Horde Groupware 5.2.17
Horde Groupware 5.2.22
Debian Debian Linux 8.0
Debian Debian Linux 9.0
4.3
CVSSv2
CVE-2015-8807
Cross-site scripting (XSS) vulnerability in the _renderVarInput_number function in horde/framework/Core/lib/Horde/Core/Ui/VarRenderer/Html.php in Horde Groupware prior to 5.2.12 and Horde Groupware Webmail Edition prior to 5.2.12 allows remote malicious users to inject arbitrary ...
Fedoraproject Fedora 23
Fedoraproject Fedora 22
Horde Groupware 5.2.11
Debian Debian Linux 8.0
6.8
CVSSv2
CVE-2015-7984
Multiple cross-site request forgery (CSRF) vulnerabilities in Horde prior to 5.2.8, Horde Groupware prior to 5.2.11, and Horde Groupware Webmail Edition prior to 5.2.11 allow remote malicious users to hijack the authentication of administrators for requests that execute arbitrary...
Horde Groupware
Horde Horde Application Framework
Debian Debian Linux 8.0
1 EDB exploit
7.5
CVSSv2
CVE-2014-1691
The framework/Util/lib/Horde/Variables.php script in the Util library in Horde prior to 5.1.1 allows remote malicious users to conduct object injection attacks and execute arbitrary PHP code via a crafted serialized object in the _formvars form.
Horde Horde Application Framework 5.0.4
Horde Horde Application Framework 5.0.2
Horde Horde Application Framework 5.0.1
Horde Horde Application Framework 5.0.0
Horde Horde Application Framework
Horde Horde Application Framework 5.0.3
1 EDB exploit
6.8
CVSSv2
CVE-2010-3694
Cross-site request forgery (CSRF) vulnerability in the Horde Application Framework prior to 3.3.9 allows remote malicious users to hijack the authentication of unspecified victims for requests to a preference form.
Horde Horde Application Framework 1.0.3
Horde Horde Application Framework 1.1.1
Horde Horde Application Framework 2.0
Horde Horde Application Framework 2.1
Horde Horde Application Framework 2.2.7
Horde Horde Application Framework 2.2.8
Horde Horde Application Framework 3.0.3
Horde Horde Application Framework 3.0.9
Horde Horde Application Framework 3.1.3
Horde Horde Application Framework 3.1.4
Horde Horde Application Framework 3.2.1
Horde Horde Application Framework 3.2.3
Horde Horde Application Framework 3.3.5
Horde Horde Application Framework 3.3.6
Horde Horde Application Framework 3.1.8
Horde Horde Application Framework 3.0.5
Horde Horde Application Framework 3.2
Horde Horde Application Framework 3.0.8
Horde Horde Application Framework 1.3.3
Horde Horde Application Framework 1.3.4
Horde Horde Application Framework 2.2
Horde Horde Application Framework 2.2.1
4.3
CVSSv2
CVE-2010-3077
Cross-site scripting (XSS) vulnerability in util/icon_browser.php in the Horde Application Framework prior to 3.3.9 allows remote malicious users to inject arbitrary web script or HTML via the subdir parameter.
Horde Horde Application Framework 1.0.3
Horde Horde Application Framework 1.1.1
Horde Horde Application Framework 2.0
Horde Horde Application Framework 2.1
Horde Horde Application Framework 2.2.6
Horde Horde Application Framework 2.2.7
Horde Horde Application Framework 3.0.3
Horde Horde Application Framework 3.0.9
Horde Horde Application Framework 3.1.3
Horde Horde Application Framework 3.1.4
Horde Horde Application Framework 3.2
Horde Horde Application Framework 3.2.1
Horde Horde Application Framework 3.3.5
Horde Horde Application Framework 3.3.6
Horde Horde Application Framework 3.1.8
Horde Horde Application Framework 3.0.5
Horde Horde Application Framework 3.0.8
Horde Horde Application Framework 1.3.2
Horde Horde Application Framework 1.3.5
Horde Horde Application Framework 2.2.4
Horde Horde Application Framework 2.2.5
Horde Horde Application Framework 3.0.1
1 EDB exploit
4.3
CVSSv2
CVE-2009-3701
Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in Horde Application Framework prior to 3.3.6, Horde Groupware prior to 1.2.5, and Horde Groupware Webmail Edition prior to 1.2.5 allow remote malicious users to inject arbitrary web script or HTM...
Horde Application Framework 3.3.4
Horde Application Framework 2.1
Horde Application Framework 2.1.3
Horde Application Framework 3.0.4
Horde Application Framework 3.0
Horde Application Framework 3.0.9
Horde Application Framework 3.2.1
Horde Groupware 1.2.3
Horde Groupware
Horde Groupware 1.0.1
Horde Groupware 1.2
Horde Groupware 1.1.5
Horde Application Framework 2.2.4 Rc1
Horde Application Framework 2.2.5
Horde Application Framework 2.2.3
Horde Application Framework 3.0.1
Horde Application Framework 2.2.6
Horde Application Framework 2.0
Horde Application Framework 3.0.2
Horde Application Framework 3.0.3
Horde Application Framework 3.1
Horde Application Framework 3.1.1
4 EDB exploits
4.3
CVSSv2
CVE-2009-4363
Text_Filter/lib/Horde/Text/Filter/Xss.php in Horde Application Framework prior to 3.3.6, Horde Groupware prior to 1.2.5, and Horde Groupware Webmail Edition prior to 1.2.5 does not properly handle data: URIs, which allows remote malicious users to conduct cross-site scripting (XS...
Horde Application Framework 2.2.4 Rc1
Horde Application Framework 2.2.5
Horde Application Framework 2.2.6
Horde Application Framework 2.0
Horde Application Framework 3.0.7
Horde Application Framework 3.1
Horde Application Framework 3.3.4
Horde Application Framework 2.2.4
Horde Application Framework 2.1
Horde Application Framework 2.2
Horde Application Framework 3.0
Horde Application Framework 3.2.2
Horde Application Framework 3.2.1
Horde Application Framework 3.2
Horde Groupware 1.2.3
Horde Groupware 1.2
Horde Groupware 1.1.2
Horde Application Framework
Horde Application Framework 2.1.3
Horde Application Framework 2.2.1
Horde Application Framework 3.3
Horde Application Framework 3.0.6
4.3
CVSSv2
CVE-2009-3237
Multiple cross-site scripting (XSS) vulnerabilities in Horde Application Framework 3.2 prior to 3.2.5 and 3.3 prior to 3.3.5; Groupware 1.1 prior to 1.1.6 and 1.2 prior to 1.2.4; and Groupware Webmail Edition 1.1 prior to 1.1.6 and 1.2 prior to 1.2.4; allow remote malicious users...
Horde Horde Application Framework 3.2
Horde Horde Application Framework 3.3.2
Horde Horde Application Framework 3.3.3
Horde Horde Groupware 1.2.1
Horde Horde Groupware 1.2.2
Horde Horde Application Framework 3.2.1
Horde Horde Application Framework 3.2.2
Horde Horde Application Framework 3.3.4
Horde Horde Groupware 1.1.1
Horde Horde Groupware 1.2.3
Horde Horde Application Framework 3.3
Horde Horde Application Framework 3.3.1
Horde Horde Groupware 1.1.4
Horde Horde Groupware 1.2
Horde Horde Application Framework 3.2.3
Horde Horde Application Framework 3.2.4
Horde Horde Groupware 1.1.2
Horde Horde Groupware 1.1.3
Horde Horde Groupware 1.1.5
Horde Groupware 1.1
Horde Groupware 1.1.3
Horde Groupware 1.2.3
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-29895
blind SQL injection
CVE-2024-5064
CVE-2023-52677
CVE-2023-52682
CVE-2024-30051
CVE-2024-35849
remote attackers
remote
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »