Skip to main content

Vendor/product archive

horde / application_framework CVEs

Beta · best-effort

8 CVEs tagged to horde / application_framework0 Critical, 1 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2009-4363

Published Dec 21, 2009

Text_Filter/lib/Horde/Text/Filter/Xss.php in Horde Application Framework before 3.3.6, Horde Groupware before 1.2.5, and Horde Groupware Webmail Edition before 1.2.5 does not prop…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3236

Published Sep 17, 2009

The form library in Horde Application Framework 3.2 before 3.2.5 and 3.3 before 3.3.5; Groupware 1.1 before 1.1.6 and 1.2 before 1.2.4; and Groupware Webmail Edition 1.1 before 1.…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4256

Published Aug 21, 2006

index.php in Horde Application Framework before 3.1.2 allows remote attackers to include web pages from other sites, which could be useful for phishing attacks, via a URL in the u…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1491

Published Mar 29, 2006

Eval injection vulnerability in Horde Application Framework versions 3.0 before 3.0.10 and 3.1 before 3.1.1 allows remote attackers to execute arbitrary code via the help viewer.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0961

Published May 2, 2005

Cross-site scripting (XSS) vulnerability in Horde 3.0.4 before 3.0.4-RC2 allows remote attackers to inject arbitrary web script or HTML via the parent frame title.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2741

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in the "help window" (help.php) in Horde Application Framework 2.2.6 allows remote attackers to inject arbitrary web script or HTML via th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1