CVE Vulnerabilities

CVE-2006-4256

Published: Aug 21, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

index.php in Horde Application Framework before 3.1.2 allows remote attackers to include web pages from other sites, which could be useful for phishing attacks, via a URL in the url parameter, aka cross-site referencing. NOTE: some sources have referred to this issue as XSS, but it is different than classic XSS.

Affected Software

NameVendorStart VersionEnd Version
Application_frameworkHorde3.0 (including)3.0 (including)
Application_frameworkHorde3.0.1 (including)3.0.1 (including)
Application_frameworkHorde3.0.2 (including)3.0.2 (including)
Application_frameworkHorde3.0.3 (including)3.0.3 (including)
Application_frameworkHorde3.0.4 (including)3.0.4 (including)
Application_frameworkHorde3.0.4_rc1 (including)3.0.4_rc1 (including)
Application_frameworkHorde3.0.4_rc2 (including)3.0.4_rc2 (including)
Application_frameworkHorde3.0.6 (including)3.0.6 (including)
Application_frameworkHorde3.0.7 (including)3.0.7 (including)
Application_frameworkHorde3.0.8 (including)3.0.8 (including)
Application_frameworkHorde3.0.9 (including)3.0.9 (including)
Application_frameworkHorde3.1 (including)3.1 (including)
Application_frameworkHorde3.1.1 (including)3.1.1 (including)
Horde3Ubuntudapper*
Horde3Ubuntudevel*
Horde3Ubuntuedgy*
Horde3Ubuntufeisty*
Horde3Ubuntugutsy*
Horde3Ubuntuhardy*
Horde3Ubuntuintrepid*
Horde3Ubuntujaunty*
Horde3Ubuntukarmic*

References