CVE-2008-3824
Horde 3.1.x-3.1.9, Horde 3.2.x-3.2.2, Popoon r22196 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in (1) Text_Filter/Filter/xss.php in Horde 3.1.x before 3.1.9 and 3.2.x before 3.2.2 and (2) externalinput.php in Popoon r22196 and earlier allows remote attackers to inject arbitrary web script or HTML by using / (slash) characters as replacements for spaces in an HTML e-mail message.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Alexios Fakos · textwebappsphp
https://www.exploit-db.com/exploits/32353
References (15)
Scores
EPSS
0.0087
EPSS Percentile
75.0%
Classification
CWE
CWE-79
Status
draft
Affected Products (11)
horde/horde
horde/horde
horde/horde
horde/horde
horde/horde
horde/horde
horde/horde
horde/horde
horde/horde
horde/horde
popoon/popoon
< r22196
Timeline
Published
Sep 12, 2008
Tracked Since
Feb 18, 2026