5
CVSSv2

CVE-2006-3549

Published: 13/07/2006 Updated: 18/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

services/go.php in Horde Application Framework 3.0.0 up to and including 3.0.10 and 3.1.0 up to and including 3.1.1 does not properly restrict its image proxy capability, which allows remote malicious users to perform "Web tunneling" attacks and use the server as a proxy via (1) http, (2) https, and (3) ftp URL in the url parameter, which is requested from the server.

Vulnerable Product Search on Vulmon Subscribe to Product

horde horde application framework 3.0.4

horde horde application framework 3.0.5

horde horde application framework 3.0.0

horde horde application framework 3.0.6

horde horde application framework 3.0.7

horde horde application framework 3.0.1

horde horde application framework 3.0.10

horde horde application framework 3.0.8

horde horde application framework 3.0.9

horde horde application framework 3.0.2

horde horde application framework 3.0.3

horde horde application framework 3.1.0

horde horde application framework 3.1.1

Vendor Advisories

Several remote vulnerabilities have been discovered in the Horde web application framework The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2006-3548 Moritz Naumann discovered that Horde allows remote attackers to inject arbitrary web script or HTML in the context of a logged in user (cross ...