[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255116

 
 

909

 
 

198683

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-1765 horde3 -- Multiple vulnerabilities

ID: oval:org.mitre.oval:def:8165Date: (C)2009-12-15   (M)2021-06-06
Class: PATCHFamily: unix




Several vulnerabilities have been found in horde3, the horde web application framework. The Common Vulnerabilities and Exposures project identifies the following problems: Gunnar Wrobel discovered a directory traversal vulnerability, which allows attackers to include and execute arbitrary local files via the driver parameter in Horde_Image. It was discovered that an attacker could perform a cross-site scripting attack via the contact name, which allows attackers to inject arbitrary html code. This requires that the attacker has access to create contacts. It was discovered that the horde XSS filter is prone to a cross-site scripting attack, which allows attackers to inject arbitrary html code. This is only exploitable when Internet Explorer is used.

Platform:
Debian 4.0
Product:
horde3
Reference:
DSA-1765
CVE-2009-0932
CVE-2008-3330
CVE-2008-5917
CVE    3
CVE-2008-3330
CVE-2008-5917
CVE-2009-0932
CPE    1
cpe:/o:debian:debian_linux:4.0

© SecPod Technologies