CVE-2009-3701

Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in Horde Application Framework before 3.3.6, Horde Groupware before 1.2.5, and Horde Groupware Webmail Edition before 1.2.5 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) phpshell.php, (2) cmdshell.php, or (3) sqlshell.php in admin/, related to the PHP_SELF variable.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
VendorProductVersion
hordeapplication_framework
𝑥
≤ 3.3.5
hordeapplication_framework
2.0
hordeapplication_framework
2.1
hordeapplication_framework
2.1.3
hordeapplication_framework
2.2
hordeapplication_framework
2.2.1
hordeapplication_framework
2.2.3
hordeapplication_framework
2.2.4
hordeapplication_framework
2.2.4_rc1:_rc1
hordeapplication_framework
2.2.5
hordeapplication_framework
2.2.6
hordeapplication_framework
3.0
hordeapplication_framework
3.0.1
hordeapplication_framework
3.0.2
hordeapplication_framework
3.0.3
hordeapplication_framework
3.0.4
hordeapplication_framework
3.0.6
hordeapplication_framework
3.0.7
hordeapplication_framework
3.0.8
hordeapplication_framework
3.0.9
hordeapplication_framework
3.1
hordeapplication_framework
3.1.1
hordeapplication_framework
3.2
hordeapplication_framework
3.2.1
hordeapplication_framework
3.2.2
hordeapplication_framework
3.2.3
hordeapplication_framework
3.2.4
hordeapplication_framework
3.3
hordeapplication_framework
3.3.1
hordeapplication_framework
3.3.2
hordeapplication_framework
3.3.3
hordeapplication_framework
3.3.4
hordegroupware
𝑥
≤ 1.2.4
hordegroupware
1.0
hordegroupware
1.0.1
hordegroupware
1.0.2
hordegroupware
1.0.3
hordegroupware
1.0.4
hordegroupware
1.0.5
hordegroupware
1.1
hordegroupware
1.1.1
hordegroupware
1.1.2
hordegroupware
1.1.3
hordegroupware
1.1.4
hordegroupware
1.1.5
hordegroupware
1.2
hordegroupware
1.2:rc1
hordegroupware
1.2.1
hordegroupware
1.2.2
hordegroupware
1.2.3
hordegroupware
𝑥
≤ 1.2.4
hordegroupware
1.0
hordegroupware
1.0:rc1
hordegroupware
1.0:rc2
hordegroupware
1.0.1
hordegroupware
1.0.2
hordegroupware
1.0.3
hordegroupware
1.0.4
hordegroupware
1.0.5
hordegroupware
1.0.6
hordegroupware
1.0.7
hordegroupware
1.0.8
hordegroupware
1.1
hordegroupware
1.1:rc1
hordegroupware
1.1:rc2
hordegroupware
1.1:rc3
hordegroupware
1.1:rc4
hordegroupware
1.1.1
hordegroupware
1.1.2
hordegroupware
1.1.3
hordegroupware
1.1.4
hordegroupware
1.1.5
hordegroupware
1.1.6
hordegroupware
1.2
hordegroupware
1.2:rc1
hordegroupware
1.2.1
hordegroupware
1.2.2
hordegroupware
1.2.3
hordegroupware
1.2.3:rc1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
horde3
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
not-affected
karmic
ignored
jaunty
Fixed 3.2.2+debian0-2+lenny2build0.9.04.1
released
intrepid
ignored
hardy
ignored
dapper
ignored