CVE-2009-2360
Horde Passwd <3.1.1 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in passwd/main.php in the Passwd module before 3.1.1 for Horde allows remote attackers to inject arbitrary web script or HTML via the backend parameter.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by anonymous · textwebappsphp
https://www.exploit-db.com/exploits/33065
References (8)
Scores
EPSS
0.0109
EPSS Percentile
77.7%
Classification
CWE
CWE-79
Status
published
Affected Products (7)
horde/passwd
< 3.1
horde/passwd
horde/passwd
horde/passwd
horde/passwd
horde/passwd
n/a/n/a
Timeline
Published
Jul 08, 2009
Tracked Since
Feb 18, 2026