CVE-2010-3077
Title: Horde Horde Application Framework Cross-Site Scripting (XSS)
XSS
Proof Of Concept
PoC Available for CVE-2010-3077
CWE Category
CWE-79
Published Date
Nov 09, 2010
Modified Date
Jun 16, 2026
Exploit Status
Available
Score
4.3
CVSS v2.0
Exploit Probability (EPSS)
3.89%
Vulnerability Summary
CVE-2010-3077: Cross-site scripting (XSS) vulnerability in util/icon_browser.php in the Horde Application Framework before 3.3.9 allows remote attackers to inject arbitrary web script or HTML via the subdir parameter.
Impacted Vendors
Reference Links
http://git.horde.org/diff.php/horde/util/icon_browser.php?rt=horde-git&r1=a978a35c3e95e784253508fd4333d2fbb64830b6&r2=9342addbd2b95f184f230773daa4faf5ef6d65e9
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050408.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050423.html
http://lists.horde.org/archives/announce/2010/000557.html
http://seclists.org/fulldisclosure/2010/Sep/82
http://secunia.com/advisories/42140
https://bugzilla.redhat.com/show_bug.cgi?id=630687
http://git.horde.org/diff.php/horde/util/icon_browser.php?rt=horde-git&r1=a978a35c3e95e784253508fd4333d2fbb64830b6&r2=9342addbd2b95f184f230773daa4faf5ef6d65e9
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050408.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050423.html
http://lists.horde.org/archives/announce/2010/000557.html
http://seclists.org/fulldisclosure/2010/Sep/82
http://secunia.com/advisories/42140
https://bugzilla.redhat.com/show_bug.cgi?id=630687
CVSS v2.0
Source Entity
[email protected]
Severity
MEDIUM
4.3
Access Vector
N/A
Authentication
N/A
RAW VECTOR
AV:N/AC:M/Au:N/C:N/I:P/A:N
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2010-3077 Exploits & PoCs (Proof Of Concept)
Exploit-DB
https://www.exploit-db.com/exploits/34605
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
N/A
Complexity
N/A
Privileges
N/A
Interaction
NONE
CVSS Vector String
AV:N/AC:M/Au:N/C:N/I:P/A:N
Affected Stack
No specific products linked.