6.8
CVSSv2

CVE-2006-2195

Published: 15/06/2006 Updated: 20/07/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in horde 3 (horde3) prior to 3.1.1 allows remote malicious users to inject arbitrary web script or HTML via (1) templates/problem/problem.inc and (2) test.php.

Vulnerable Product Search on Vulmon Subscribe to Product

horde horde 3.0

horde horde 3.0.6

horde horde 3.0.7

horde horde 3.0.1

horde horde 3.0.2

horde horde 3.0.8

horde horde

horde horde 3.0.4_rc1

horde horde 3.0.4_rc2

horde horde 3.0.3

horde horde 3.0.4

Vendor Advisories

Michael Marek discovered that the Horde web application framework performs insufficient input sanitising, which might lead to the injection of web script code through cross-site scripting The old stable distribution (woody) does not contain horde3 packages For the stable distribution (sarge) this problem has been fixed in version 304-4sarge4 F ...

Exploits

Horde versions 311 and 3010 suffer from multiple cross site scripting issues ...