4.3
CVSSv2

CVE-2009-3237

Published: 17/09/2009 Updated: 18/06/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Horde Application Framework 3.2 prior to 3.2.5 and 3.3 prior to 3.3.5; Groupware 1.1 prior to 1.1.6 and 1.2 prior to 1.2.4; and Groupware Webmail Edition 1.1 prior to 1.1.6 and 1.2 prior to 1.2.4; allow remote malicious users to inject arbitrary web script or HTML via the (1) crafted number preferences that are not properly handled in the preference system (services/prefs.php), as demonstrated by the sidebar_width parameter; or (2) crafted unknown MIME "text parts" that are not properly handled in the MIME viewer library (config/mime_drivers.php).

Vulnerable Product Search on Vulmon Subscribe to Product

horde horde application framework 3.2

horde horde application framework 3.3.2

horde horde application framework 3.3.3

horde horde groupware 1.2.1

horde horde groupware 1.2.2

horde horde application framework 3.2.1

horde horde application framework 3.2.2

horde horde application framework 3.3.4

horde horde groupware 1.1.1

horde horde groupware 1.2.3

horde horde application framework 3.3

horde horde application framework 3.3.1

horde horde groupware 1.1.4

horde horde groupware 1.2

horde horde application framework 3.2.3

horde horde application framework 3.2.4

horde horde groupware 1.1.2

horde horde groupware 1.1.3

horde horde groupware 1.1.5

horde groupware 1.1

horde groupware 1.1.3

horde groupware 1.2.3

horde groupware 1.1.4

horde groupware 1.2

horde groupware 1.1.6

horde groupware 1.2.1

horde groupware 1.2.2

horde groupware 1.1.2

horde groupware 1.1.1

Vendor Advisories

Several vulnerabilities have been found in horde3, the horde web application framework The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-3237 It has been discovered that horde3 is prone to cross-site scripting attacks via crafted number preferences or inline MIME text parts when using text/plain as MIME ...