📦

horde

Vendor: horde

Actively Exploited 0 CISA KEV List
PoC / Exploits 5 Code Available
Total RCEs 2 Remote Access
Total CVEs 38 Total Indexed
Avg. EPSS 7.88% Exploit Prob.
Latest CVE CVE-2012-0209 Sep 25

Security Vulnerability Index

Page 2 / 4
4.3 CVSS

Cross-site scripting (XSS) vulnerability in horde/imp/search.php in Horde IMP H3 before 4.1.3 allows remote attackers to include arbitrary web script or HTML via multiple unspecified vectors related to folder names, as injected into the vfolder_label form field in the IMP search screen.

EPSS: 1.68%
4.3 CVSS

Multiple cross-site scripting (XSS) vulnerabilities in Horde Application Framework 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1 allow remote attackers to inject arbitrary web script or HTML via a (1) javascript URI or an external (2) http, (3) https, or (4) ftp URI in the url parameter in services/go.php (aka the dereferrer), (5) a javascript URI in the module parameter in services/help (aka the help viewer), and (6) the name parameter in services/problem.php (aka the problem reporting screen).

EPSS: 2.06%
6.8 CVSS

Cross-site scripting (XSS) vulnerability in horde 3 (horde3) before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via (1) templates/problem/problem.inc and (2) test.php.

EPSS: 2.24%
5.0 CVSS
CVE-2006-1260
Exploit Found

Horde Application Framework 3.0.9 allows remote attackers to read arbitrary files via a null character in the url parameter in services/go.php, which bypasses a sanity check.

EPSS: 12.17%
5.8 CVSS

Multiple cross-site scripting (XSS) vulnerabilities in Horde before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) gzip/tar and (2) css MIME viewers, which do not filter or escape dangerous HTML when extracting and displaying attachments.

EPSS: 1.44%
10.0 CVSS

The default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain access.

EPSS: 7.99%
4.3 CVSS

Unspecified cross-site scripting (XSS) vulnerability in Horde before 2.2.9 allows remote attackers to inject arbitrary web script or HTML via "not properly escaped error messages".

EPSS: 1.71%
4.3 CVSS

Multiple cross-site scripting (XSS) vulnerabilities in Horde 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to prefs.php or (2) url parameter to index.php.

EPSS: 1.29%
6.4 CVSS

Horde before 2.2.4 allows remote malicious web sites to steal session IDs and read or create arbitrary email by stealing the ID from a referrer URL.

EPSS: 1.10%
7.5 CVSS

Cross-site scripting vulnerability in status.php3 for IMP 2.2.8 and HORDE 1.2.7 allows remote attackers to execute arbitrary web script and steal cookies of other IMP/HORDE users via the script parameter.

EPSS: 1.85%