Description
Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in Horde Application Framework before 3.3.6, Horde Groupware before 1.2.5, and Horde Groupware Webmail Edition before 1.2.5 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) phpshell.php, (2) cmdshell.php, or (3) sqlshell.php in admin/, related to the PHP_SELF variable.
Exploits (4)
exploitdb
WRITEUP
VERIFIED
by Juan Galiana Lara · textwebappsphp
https://www.exploit-db.com/exploits/10512
exploitdb
WORKING POC
VERIFIED
by Juan Galiana Lara · textwebappsphp
https://www.exploit-db.com/exploits/33406
exploitdb
WORKING POC
VERIFIED
by Juan Galiana Lara · textwebappsphp
https://www.exploit-db.com/exploits/33408
exploitdb
WRITEUP
VERIFIED
by Juan Galiana Lara · textwebappsphp
https://www.exploit-db.com/exploits/33407
References (13)
Core 13
Core References
Various Sources x_refsource_confirm
http://cvs.horde.org/diff.php/horde/docs/CHANGES?r1=1.515.2.559&r2=1.515.2.589&ty=h
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/37823
Mailing List mailing-list
x_refsource_mlist
http://marc.info/?l=horde-announce&m=126100750018478&w=2
Exploit mailing-list
x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2009-12/0388.html
Patch mailing-list
x_refsource_mlist
http://lists.horde.org/archives/announce/2009/000529.html
Patch, Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/3549
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/508531/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/54817
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/37351
Patch mailing-list
x_refsource_mlist
http://marc.info/?l=horde-announce&m=126101076422179&w=2
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/37709
Patch, Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/3572
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1023365
Scores
EPSS
0.0219
EPSS Percentile
84.5%
Details
CWE
CWE-79
Status
published
Products (48)
horde/application_framework
2.0
horde/application_framework
2.1
horde/application_framework
2.1.3
horde/application_framework
2.2
horde/application_framework
2.2.1
horde/application_framework
2.2.3
horde/application_framework
2.2.4
horde/application_framework
2.2.4_rc1
horde/application_framework
2.2.5
horde/application_framework
2.2.6
... and 38 more
Published
Dec 21, 2009
Tracked Since
Feb 18, 2026