4.3
CVSSv2

CVE-2006-4256

Published: 21/08/2006 Updated: 17/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

index.php in Horde Application Framework prior to 3.1.2 allows remote malicious users to include web pages from other sites, which could be useful for phishing attacks, via a URL in the url parameter, aka "cross-site referencing." NOTE: some sources have referred to this issue as XSS, but it is different than classic XSS.

Vulnerable Product Search on Vulmon Subscribe to Product

horde application framework 3.0

horde application framework 3.0.1

horde application framework 3.0.7

horde application framework 3.0.8

horde application framework 3.0.4_rc2

horde application framework 3.0.6

horde application framework 3.0.4

horde application framework 3.0.4_rc1

horde application framework 3.1.1

horde application framework 3.0.2

horde application framework 3.0.3

horde application framework 3.0.9

horde application framework 3.1

Vendor Advisories

Several remote vulnerabilities have been discovered in the Horde web application framework The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2006-3548 Moritz Naumann discovered that Horde allows remote attackers to inject arbitrary web script or HTML in the context of a logged in user (cross ...