Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
horde groupware vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2008-1974
Cross-site scripting (XSS) vulnerability in addevent.php in Horde Kronolith 2.1.7, Groupware Webmail Edition 1.0.6, and Groupware 1.0.5 allows remote malicious users to inject arbitrary web script or HTML via the url parameter.
Horde Groupware 1.0.5
Horde Groupware Webmail Edition 1.0.6
1 EDB exploit
6
CVSSv2
CVE-2008-1284
Directory traversal vulnerability in Horde 3.1.6, Groupware prior to 1.0.5, and Groupware Webmail Edition prior to 1.0.6, when running with certain configurations, allows remote authenticated users to read and execute arbitrary files via ".." sequences and a null byte i...
Horde Groupware Webmail Edition
Horde Horde 3.1.6
Horde Groupware
4.9
CVSSv2
CVE-2008-0807
lib/Driver/sql.php in Turba 2 (turba2) Contact Manager H3 2.1.x prior to 2.1.7 and 2.2.x prior to 2.2-RC3, as used in products such as Horde Groupware prior to 1.0.4 and Horde Groupware Webmail Edition prior to 1.0.5, does not properly check access rights, which allows remote aut...
Horde Groupware 1.0.3
Horde Groupware Webmail Edition 1.0.4
Horde Turba Contact Manager 2.1.6
5.8
CVSSv2
CVE-2007-6018
IMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3 does not validate unspecified HTTP requests, which allows remote malicious users to (1) delete arbitrary e-mail messages via a modified numeric ID or (2) "purge" delet...
Horde Framework 3.1.5
Horde Imp 4.1.5
Horde Groupware Webmail Edition 1.0.3
Horde Horde 3.1.5
4.3
CVSSv2
CVE-2007-1679
Multiple cross-site scripting (XSS) vulnerabilities in Horde Groupware Webmail 1.0 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors in (1) imp/search.php and (2) ingo/rule.php. NOTE: this issue has been disputed by the vendor, noting...
Horde Groupware 1.0
5.1
CVSSv2
CVE-2007-0579
Unspecified vulnerability in the calendar component in Horde Groupware Webmail Edition prior to 1.0, and Groupware prior to 1.0, allows remote malicious users to include certain files via unspecified vectors. NOTE: some of these details are obtained from third party information.
Horde Groupware 1.0 Rc3
Horde Groupware 1.0 Rc2
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6