Lucene search

K
ubuntucveUbuntu.comUB:CVE-2006-4256
HistoryAug 21, 2006 - 12:00 a.m.

CVE-2006-4256

2006-08-2100:00:00
ubuntu.com
ubuntu.com
19

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.019

Percentile

88.5%

index.php in Horde Application Framework before 3.1.2 allows remote
attackers to include web pages from other sites, which could be useful for
phishing attacks, via a URL in the url parameter, aka “cross-site
referencing.” NOTE: some sources have referred to this issue as XSS, but it
is different than classic XSS.

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.019

Percentile

88.5%

Related for UB:CVE-2006-4256