CVE-2008-5917
Horde Application Framework <3.3 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the XSS filter (framework/Text_Filter/Filter/xss.php) in Horde Application Framework 3.2.2 and 3.3, when Internet Explorer is being used, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to style attributes.
References (6)
Scores
EPSS
0.0052
EPSS Percentile
66.5%
Classification
CWE
CWE-79
Status
published
Affected Products (3)
horde/application_framework
horde/application_framework
n/a/n/a
Timeline
Published
Jan 21, 2009
Tracked Since
Feb 18, 2026