CVE-2009-3701
Horde Application Framework < 3.3.6 - Cross-Site Scripting via PATH_INFO
Title source: llmExploitation Summary
EIP tracks 4 public exploits for CVE-2009-3701. PoCs published by Juan Galiana Lara.
AI-analyzed exploit summary This is a vulnerability advisory detailing a Cross-Site Scripting (XSS) vulnerability in Horde 3.3.5 due to improper filtering of the PHP_SELF variable. The advisory includes a proof-of-concept demonstrating the XSS via crafted URLs.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in Horde Application Framework before 3.3.6, Horde Groupware before 1.2.5, and Horde Groupware Webmail Edition before 1.2.5 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) phpshell.php, (2) cmdshell.php, or (3) sqlshell.php in admin/, related to the PHP_SELF variable.
Exploits (4)
This is a vulnerability advisory detailing a Cross-Site Scripting (XSS) vulnerability in Horde 3.3.5 due to improper filtering of the PHP_SELF variable. The advisory includes a proof-of-concept demonstrating the XSS via crafted URLs.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Horde Framework versions prior to 3.3.6. The PoC shows how an attacker can inject arbitrary JavaScript code via a crafted URL, potentially leading to session hijacking or other client-side attacks.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Horde Framework versions prior to 3.3.6. The PoC shows how an attacker can inject arbitrary JavaScript code via a crafted URL, potentially leading to session hijacking or other client-side attacks.
The provided text describes a cross-site scripting (XSS) vulnerability in the Horde Framework prior to version 3.3.6. It includes a proof-of-concept URL demonstrating the vulnerability but lacks executable exploit code.