Multiple cross-site scripting (XSS) vulnerabilities in Horde 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to prefs.php or (2) url parameter to index.php.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Horde | Horde | 3.0 (including) | 3.0 (including) |
| Horde2 | Ubuntu | dapper | * |
| Horde2 | Ubuntu | edgy | * |