Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
horde application framework vulnerabilities and exploits
(subscribe to this query)
NA
CVE_2022_40684
Official Writeup - Simple CTF 2.0 Created: April 23, 2024 7:50 PM Today I completed an other room on TryHackMe with a simple file-upload vulnerability which I built. I have tried for dancing around this whole CTF machine and getting a lot of walls of challenges in the end it co...
1 Github repository
8.8
CVSSv3
CVE-2019-9858
Remote code execution exists in Horde Groupware Webmail 5.2.22 and 5.2.17. Horde/Form/Type.php contains a vulnerable class that handles image upload in forms. When the Horde_Form_Type_image method onSubmit() is called on uploads, it invokes the functions getImage() and _getUpload...
Horde Groupware 5.2.17
Horde Groupware 5.2.22
Debian Debian Linux 8.0
Debian Debian Linux 9.0
6.1
CVSSv3
CVE-2015-8807
Cross-site scripting (XSS) vulnerability in the _renderVarInput_number function in horde/framework/Core/lib/Horde/Core/Ui/VarRenderer/Html.php in Horde Groupware prior to 5.2.12 and Horde Groupware Webmail Edition prior to 5.2.12 allows remote malicious users to inject arbitrary ...
Fedoraproject Fedora 22
Fedoraproject Fedora 23
Horde Groupware 5.2.11
Debian Debian Linux 8.0
NA
CVE-2015-7984
Multiple cross-site request forgery (CSRF) vulnerabilities in Horde prior to 5.2.8, Horde Groupware prior to 5.2.11, and Horde Groupware Webmail Edition prior to 5.2.11 allow remote malicious users to hijack the authentication of administrators for requests that execute arbitrary...
Horde Horde Application Framework
Horde Groupware
Debian Debian Linux 8.0
1 EDB exploit
NA
CVE-2014-1691
The framework/Util/lib/Horde/Variables.php script in the Util library in Horde prior to 5.1.1 allows remote malicious users to conduct object injection attacks and execute arbitrary PHP code via a crafted serialized object in the _formvars form.
Horde Horde Application Framework 5.0.1
Horde Horde Application Framework 5.0.4
Horde Horde Application Framework
Horde Horde Application Framework 5.0.2
Horde Horde Application Framework 5.0.3
Horde Horde Application Framework 5.0.0
1 EDB exploit
NA
CVE-2010-3077
Cross-site scripting (XSS) vulnerability in util/icon_browser.php in the Horde Application Framework prior to 3.3.9 allows remote malicious users to inject arbitrary web script or HTML via the subdir parameter.
Horde Horde Application Framework 3.0.11
Horde Horde Application Framework 2.0
Horde Horde Application Framework 3.2.3
Horde Horde Application Framework 3.0
Horde Horde Application Framework 3.3.4
Horde Horde Application Framework 3.2
Horde Horde Application Framework 3.1.4
Horde Horde Application Framework 2.2.5
Horde Horde Application Framework 3.1
Horde Horde Application Framework 3.0.4
Horde Horde Application Framework 3.0.6
Horde Horde Application Framework 3.1.9
Horde Horde Application Framework 3.1.8
Horde Horde Application Framework 3.1.2
Horde Horde Application Framework 2.2.9
Horde Horde Application Framework 2.2.3
Horde Horde Application Framework 1.3.3
Horde Horde Application Framework 3.0.5
Horde Horde Application Framework 1.3.1
Horde Horde Application Framework 3.0.10
Horde Horde Application Framework 3.0.1
Horde Horde Application Framework 3.3.7
1 EDB exploit
NA
CVE-2010-3694
Cross-site request forgery (CSRF) vulnerability in the Horde Application Framework prior to 3.3.9 allows remote malicious users to hijack the authentication of unspecified victims for requests to a preference form.
Horde Horde Application Framework 3.0.11
Horde Horde Application Framework 2.0
Horde Horde Application Framework 3.2.3
Horde Horde Application Framework 3.0
Horde Horde Application Framework 3.3.4
Horde Horde Application Framework 3.2
Horde Horde Application Framework 3.1.4
Horde Horde Application Framework 2.2.5
Horde Horde Application Framework 3.1
Horde Horde Application Framework 3.0.4
Horde Horde Application Framework 3.0.6
Horde Horde Application Framework 3.1.9
Horde Horde Application Framework 3.1.8
Horde Horde Application Framework 3.1.2
Horde Horde Application Framework 2.2.9
Horde Horde Application Framework 2.2.3
Horde Horde Application Framework 1.3.3
Horde Horde Application Framework 3.0.5
Horde Horde Application Framework 1.3.1
Horde Horde Application Framework 3.0.10
Horde Horde Application Framework 3.0.1
Horde Horde Application Framework 3.3.7
NA
CVE-2009-3701
Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in Horde Application Framework prior to 3.3.6, Horde Groupware prior to 1.2.5, and Horde Groupware Webmail Edition prior to 1.2.5 allow remote malicious users to inject arbitrary web script or HTM...
Horde Application Framework 3.0.2
Horde Groupware 1.1
Horde Application Framework 3.2.4
Horde Application Framework 2.1
Horde Groupware 1.0
Horde Groupware 1.2.2
Horde Application Framework 2.2.4 Rc1
Horde Groupware 1.1.5
Horde Application Framework 3.2.1
Horde Application Framework
Horde Application Framework 2.0
Horde Application Framework 3.3.2
Horde Application Framework 3.0.8
Horde Groupware 1.2.1
Horde Application Framework 3.0
Horde Groupware 1.0.2
Horde Application Framework 3.2.2
Horde Groupware
Horde Groupware 1.0.1
Horde Groupware 1.0.5
Horde Application Framework 2.2
Horde Groupware 1.1.1
4 EDB exploits
NA
CVE-2009-4363
Text_Filter/lib/Horde/Text/Filter/Xss.php in Horde Application Framework prior to 3.3.6, Horde Groupware prior to 1.2.5, and Horde Groupware Webmail Edition prior to 1.2.5 does not properly handle data: URIs, which allows remote malicious users to conduct cross-site scripting (XS...
Horde Application Framework 3.0.2
Horde Groupware 1.1
Horde Application Framework 3.2.4
Horde Application Framework 2.1
Horde Groupware 1.0
Horde Groupware 1.2.2
Horde Application Framework 2.2.4 Rc1
Horde Groupware 1.1.5
Horde Application Framework 3.2.1
Horde Application Framework
Horde Application Framework 2.0
Horde Application Framework 3.3.2
Horde Application Framework 3.0.8
Horde Groupware 1.2.1
Horde Application Framework 3.0
Horde Groupware 1.0.2
Horde Application Framework 3.2.2
Horde Groupware
Horde Groupware 1.0.1
Horde Groupware 1.0.5
Horde Application Framework 2.2
Horde Groupware 1.1.1
NA
CVE-2009-3236
The form library in Horde Application Framework 3.2 prior to 3.2.5 and 3.3 prior to 3.3.5; Groupware 1.1 prior to 1.1.6 and 1.2 prior to 1.2.4; and Groupware Webmail Edition 1.1 prior to 1.1.6 and 1.2 prior to 1.2.4; reuses temporary filenames during the upload process which allo...
Horde Groupware 1.1
Horde Application Framework 3.2.4
Horde Groupware 1.2.2
Horde Groupware 1.1.5
Horde Application Framework 3.2.1
Horde Application Framework 3.3.2
Horde Groupware 1.2.1
Horde Application Framework 3.2.2
Horde Groupware 1.1.1
Horde Application Framework 3.3.3
Horde Groupware 1.1.3
Horde Application Framework 3.3.4
Horde Application Framework 3.2.3
Horde Application Framework 3.3.1
Horde Application Framework 3.2
Horde Groupware 1.2
Horde Groupware 1.1.4
Horde Application Framework 3.3
Horde Groupware 1.1.2
Horde Groupware 1.2.3
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37316
firmware
CVE-2024-30078
CVE-2024-5995
remote code execution
logic flaw
CVE-2024-20693
CVE-2024-37315
CVE-2024-5464
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »