Lucene search

K
osvGoogleOSV:DSA-1406-1
HistoryNov 09, 2007 - 12:00 a.m.

horde3 - several vulnerabilities

2007-11-0900:00:00
Google
osv.dev
33

EPSS

0.019

Percentile

88.5%

Several remote vulnerabilities have been discovered in the Horde web
application framework. The Common Vulnerabilities and Exposures project
identifies the following problems:

Moritz Naumann discovered that Horde allows remote attackers
to inject arbitrary web script or HTML in the context of a logged
in user (cross site scripting).

This vulnerability applies to oldstable (sarge) only.

Moritz Naumann discovered that Horde does not properly restrict
its image proxy, allowing remote attackers to use the server as a
proxy.

This vulnerability applies to oldstable (sarge) only.

Marc Ruef discovered that Horde allows remote attackers to
include web pages from other sites, which could be useful for
phishing attacks.

This vulnerability applies to oldstable (sarge) only.

Moritz Naumann discovered that Horde allows remote attackers
to inject arbitrary web script or HTML in the context of a logged
in user (cross site scripting).

This vulnerability applies to both stable (etch) and oldstable (sarge).

iDefense discovered that the cleanup cron script in Horde
allows local users to delete arbitrary files.

This vulnerability applies to oldstable (sarge) only.

For the old stable distribution (sarge) these problems have been fixed in
version 3.0.4-4sarge6.

For the stable distribution (etch) these problems have been fixed in
version 3.1.3-4etch1.

For the unstable distribution (sid) these problems have been fixed in
version 3.1.4-1.

We recommend that you upgrade your horde3 package.