Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-3824. PoCs published by Alexios Fakos.
AI-analyzed exploit summary This is a proof-of-concept for a cross-site scripting (XSS) vulnerability in Horde Framework. The exploit demonstrates arbitrary JavaScript execution via an unsanitized body tag attribute.
Description
Cross-site scripting (XSS) vulnerability in (1) Text_Filter/Filter/xss.php in Horde 3.1.x before 3.1.9 and 3.2.x before 3.2.2 and (2) externalinput.php in Popoon r22196 and earlier allows remote attackers to inject arbitrary web script or HTML by using / (slash) characters as replacements for spaces in an HTML e-mail message.
Exploits (1)
This is a proof-of-concept for a cross-site scripting (XSS) vulnerability in Horde Framework. The exploit demonstrates arbitrary JavaScript execution via an unsanitized body tag attribute.