CVE-2008-3824

Horde 3.1.x-3.1.9, Horde 3.2.x-3.2.2, Popoon r22196 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in (1) Text_Filter/Filter/xss.php in Horde 3.1.x before 3.1.9 and 3.2.x before 3.2.2 and (2) externalinput.php in Popoon r22196 and earlier allows remote attackers to inject arbitrary web script or HTML by using / (slash) characters as replacements for spaces in an HTML e-mail message.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Alexios Fakos · textwebappsphp
https://www.exploit-db.com/exploits/32353

Scores

EPSS 0.0087
EPSS Percentile 75.0%

Classification

CWE
CWE-79
Status draft

Affected Products (11)

horde/horde
horde/horde
horde/horde
horde/horde
horde/horde
horde/horde
horde/horde
horde/horde
horde/horde
horde/horde
popoon/popoon < r22196

Timeline

Published Sep 12, 2008
Tracked Since Feb 18, 2026