Vulnerabilities
Vulnerable Software
Horde:  >> Horde  >> 2.2.3  Security Vulnerabilities
Horde Application Framework 3.0.9 allows remote attackers to read arbitrary files via a null character in the url parameter in services/go.php, which bypasses a sanity check.
CVSS Score
5.0
EPSS Score
0.232
Published
2006-03-19
Multiple cross-site scripting (XSS) vulnerabilities in Horde before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) gzip/tar and (2) css MIME viewers, which do not filter or escape dangerous HTML when extracting and displaying attachments.
CVSS Score
5.8
EPSS Score
0.007
Published
2005-11-22
Unspecified cross-site scripting (XSS) vulnerability in Horde before 2.2.9 allows remote attackers to inject arbitrary web script or HTML via "not properly escaped error messages".
CVSS Score
4.3
EPSS Score
0.013
Published
2005-11-16


Contact Us

Shodan ® - All rights reserved