4.3
CVSSv2

CVE-2009-3701

Published: 21/12/2009 Updated: 18/06/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 450
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in Horde Application Framework prior to 3.3.6, Horde Groupware prior to 1.2.5, and Horde Groupware Webmail Edition prior to 1.2.5 allow remote malicious users to inject arbitrary web script or HTML via the PATH_INFO to (1) phpshell.php, (2) cmdshell.php, or (3) sqlshell.php in admin/, related to the PHP_SELF variable.

Vulnerable Product Search on Vulmon Subscribe to Product

horde application framework 3.3.4

horde application framework 2.1

horde application framework 2.1.3

horde application framework 3.0.4

horde application framework 3.0

horde application framework 3.0.9

horde application framework 3.2.1

horde groupware 1.2.3

horde groupware

horde groupware 1.0.1

horde groupware 1.2

horde groupware 1.1.5

horde application framework 2.2.4_rc1

horde application framework 2.2.5

horde application framework 2.2.3

horde application framework 3.0.1

horde application framework 2.2.6

horde application framework 2.0

horde application framework 3.0.2

horde application framework 3.0.3

horde application framework 3.1

horde application framework 3.1.1

horde application framework 3.0.8

horde application framework 3.3.2

horde application framework 3.3.1

horde groupware 1.1

horde groupware 1.0.2

horde groupware 1.2.2

horde groupware 1.1.4

horde application framework 3.0.6

horde application framework 3.0.7

horde application framework 3.2.3

horde application framework 3.3.3

horde groupware 1.0

horde groupware 1.0.5

horde groupware 1.0.4

horde groupware 1.1.1

horde groupware 1.2.1

horde application framework

horde application framework 2.2.4

horde application framework 2.2

horde application framework 2.2.1

horde application framework 3.3

horde application framework 3.2.2

horde application framework 3.2.4

horde application framework 3.2

horde groupware 1.0.3

horde groupware 1.1.3

horde groupware 1.1.2

horde groupware 1.1.6

horde groupware 1.0.6

horde groupware 1.0.7

horde groupware 1.0.8

Vendor Advisories

Several vulnerabilities have been found in horde3, the horde web application framework The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-3237 It has been discovered that horde3 is prone to cross-site scripting attacks via crafted number preferences or inline MIME text parts when using text/plain as MIME ...

Exploits

Horde version 335 suffers from a cross site scripting vulnerability ...
============================================= INTERNET SECURITY AUDITORS ALERT 2009-012 - Original release date: October 13th, 2009 - Last revised: December 16th, 2009 - Discovered by: Juan Galiana Lara - CVE ID: CVE-2009-3701 - Severity: 63/10 (CVSS Base Score) ============================================= I VULNERABILITY ---------------------- ...
source: wwwsecurityfocuscom/bid/37351/info Horde Framework is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site This may help the at ...
source: wwwsecurityfocuscom/bid/37351/info Horde Framework is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site This may help the atta ...
source: wwwsecurityfocuscom/bid/37351/info Horde Framework is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site This may help the attack ...