CVE Vulnerabilities

CVE-2006-1260

Published: Mar 19, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Horde Application Framework 3.0.9 allows remote attackers to read arbitrary files via a null character in the url parameter in services/go.php, which bypasses a sanity check.

Affected Software

NameVendorStart VersionEnd Version
HordeHorde1.2 (including)1.2 (including)
HordeHorde1.2.1 (including)1.2.1 (including)
HordeHorde1.2.2 (including)1.2.2 (including)
HordeHorde1.2.3 (including)1.2.3 (including)
HordeHorde1.2.4 (including)1.2.4 (including)
HordeHorde1.2.5 (including)1.2.5 (including)
HordeHorde1.2.6 (including)1.2.6 (including)
HordeHorde1.2.7 (including)1.2.7 (including)
HordeHorde1.2.8 (including)1.2.8 (including)
HordeHorde2.0 (including)2.0 (including)
HordeHorde2.1 (including)2.1 (including)
HordeHorde2.1.3 (including)2.1.3 (including)
HordeHorde2.2 (including)2.2 (including)
HordeHorde2.2.1 (including)2.2.1 (including)
HordeHorde2.2.3 (including)2.2.3 (including)
HordeHorde2.2.4 (including)2.2.4 (including)
HordeHorde2.2.4_rc1 (including)2.2.4_rc1 (including)
HordeHorde2.2.5 (including)2.2.5 (including)
HordeHorde2.2.6 (including)2.2.6 (including)
HordeHorde2.2.7 (including)2.2.7 (including)
HordeHorde2.2.8 (including)2.2.8 (including)
HordeHorde2.2.9 (including)2.2.9 (including)
HordeHorde3.0 (including)3.0 (including)
HordeHorde3.0.1 (including)3.0.1 (including)
HordeHorde3.0.2 (including)3.0.2 (including)
HordeHorde3.0.3 (including)3.0.3 (including)
HordeHorde3.0.4 (including)3.0.4 (including)
HordeHorde3.0.4_rc1 (including)3.0.4_rc1 (including)
HordeHorde3.0.4_rc2 (including)3.0.4_rc2 (including)
HordeHorde3.0.6 (including)3.0.6 (including)
HordeHorde3.0.7 (including)3.0.7 (including)
HordeHorde3.0.8 (including)3.0.8 (including)
HordeHorde3.0.9 (including)3.0.9 (including)
Horde3Ubuntudevel*

References