7.5
CVSSv2

CVE-2006-1491

Published: 29/03/2006 Updated: 20/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Eval injection vulnerability in Horde Application Framework versions 3.0 prior to 3.0.10 and 3.1 prior to 3.1.1 allows remote malicious users to execute arbitrary code via the help viewer.

Vulnerable Product Search on Vulmon Subscribe to Product

horde application framework 3.0.4_rc2

horde application framework 3.0.6

horde application framework 3.0.4

horde application framework 3.0.4_rc1

horde application framework 3.0

horde application framework 3.0.1

horde application framework 3.0.7

horde application framework 3.0.8

horde application framework 3.0.2

horde application framework 3.0.3

horde application framework 3.0.9

horde application framework 3.1

Vendor Advisories

Several remote vulnerabilities have been discovered in the Horde web application framework, which may lead to the execution of arbitrary web script code The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2006-1260 Null characters in the URL parameter bypass a sanity check, which allowed remote attacker ...
Several remote vulnerabilities have been discovered in the Horde web application framework, which may lead to the execution of arbitrary web script code The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2005-4190 Several Cross-Site-Scripting vulnerabilities have been discovered in the "share edit wind ...

Exploits

## # Title: Horde <= 309, 310 (Help Viewer) Remote PHP Code Execution Vulnerability # Name: horde_help_modulepm # License: Artistic/BSD/GPL # Info: Trying to get the command execution exploits out of the way on milw0rmcom M's are always good # # # - This is an exploit module for the Metasploit Framework, please see # ...