Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-3077. PoCs published by Moritz Naumann.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in the Horde Application Framework, where user-supplied input is not sufficiently sanitized. The vulnerability allows arbitrary script execution in the context of the affected site, potentially leading to credential theft.
Description
Cross-site scripting (XSS) vulnerability in util/icon_browser.php in the Horde Application Framework before 3.3.9 allows remote attackers to inject arbitrary web script or HTML via the subdir parameter.
Exploits (1)
The provided text describes a cross-site scripting (XSS) vulnerability in the Horde Application Framework, where user-supplied input is not sufficiently sanitized. The vulnerability allows arbitrary script execution in the context of the affected site, potentially leading to credential theft.