Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2006-2195

Overview

Vulnerability Score 6.8 6.8
CVE Id CVE-2006-2195
Last Modified 07 Mar 2011 09:35:31
Published 15 Jun 2006 06:02:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2006-2195

Summary

Cross-site scripting (XSS) vulnerability in horde 3 (horde3) before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via (1) templates/problem/problem.inc and (2) test.php.

Vulnerable Systems

Application

  • Horde 3.0

  • Horde 3.0.1

  • Horde 3.0.2

  • Horde 3.0.3

  • Horde 3.0.4

  • Horde 3.0.4 Rc1

  • Horde 3.0.4 Rc2

  • Horde 3.0.6

  • Horde 3.0.7

  • Horde 3.0.8

  • Horde 3.0.9


References

DEBIAN - DSA-1098

XF - horde-test-problem-xss(27168)

VUPEN - ADV-2006-2356

BID - 18436

OSVDB - 26514

OSVDB - 26513

SUSE - SUSE-SR:2006:016

GENTOO - GLSA-200606-28

SECTRACK - 1016310

SECUNIA - 20960

SECUNIA - 20849

SECUNIA - 20750

SECUNIA - 20672

SECUNIA - 20661

MISC - http://overlays.gentoo.org/dev/chtekk/browser/horde/www-apps/horde/files/horde-3.1.1-xss.diff?rev=4&format=txt

CONFIRM - http://cvs.horde.org/diff.php?r1=2.25&r2=2.26&f=horde%2Ftemplates%2Fproblem%2Fproblem.inc

CONFIRM - http://cvs.horde.org/diff.php?f=horde%2Ftest.php&r1=1.145&r2=1.146

CONFIRM - http://bugs.gentoo.org/show_bug.cgi?id=136830


Last Updated: 27 May 2016 10:42:22