CVE-2004-2741
Horde Application Framework - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in the "help window" (help.php) in Horde Application Framework 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) module, (2) topic, or (3) module parameters.
References (7)
Scores
EPSS
0.0051
EPSS Percentile
66.0%
Classification
CWE
CWE-79
Status
draft
Affected Products (10)
horde/application_framework
horde/application_framework
horde/application_framework
horde/application_framework
horde/application_framework
horde/application_framework
horde/application_framework
horde/application_framework
horde/application_framework
horde/application_framework
Timeline
Published
Dec 31, 2004
Tracked Since
Feb 18, 2026