Vulnerability Name: | CVE-2006-3549 (CCN-27590) | ||||||||||||||||
Assigned: | 2006-07-05 | ||||||||||||||||
Published: | 2006-07-05 | ||||||||||||||||
Updated: | 2018-10-18 | ||||||||||||||||
Summary: | services/go.php in Horde Application Framework 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1 does not properly restrict its image proxy capability, which allows remote attackers to perform "Web tunneling" attacks and use the server as a proxy via (1) http, (2) https, and (3) ftp URL in the url parameter, which is requested from the server. | ||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N) 4.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
4.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Wed Jul 05 2006 - 16:43:30 CDT Public Advisory: Horde 3.1.1, 3.0.10 Multiple Security Issues Source: MITRE Type: CNA CVE-2006-3549 Source: CCN Type: Horde Announce Mailing List, Wed Jul 5 08:36:12 PDT 2006 Horde 3.0.11 (final) Source: CONFIRM Type: Patch http://lists.horde.org/archives/announce/2006/000287.html Source: CCN Type: Horde Announce Mailing List, Wed Jul 5 09:58:58 PDT 2006 Horde 3.1.2 (final) Source: CONFIRM Type: UNKNOWN http://lists.horde.org/archives/announce/2006/000288.html Source: MISC Type: Exploit http://moritz-naumann.com/adv/0011/hordemulti/0011.txt Source: CCN Type: SA20954 Horde Cross-Site Scripting Vulnerabilities Source: SECUNIA Type: UNKNOWN 20954 Source: SECUNIA Type: UNKNOWN 21459 Source: SECUNIA Type: UNKNOWN 27565 Source: SREASON Type: UNKNOWN 1229 Source: CCN Type: SECTRACK ID: 1016442 Horde Application Framework Input Validation Hole Permits Cross-Site Scripting Attacks Source: SECTRACK Type: Exploit 1016442 Source: DEBIAN Type: UNKNOWN DSA-1406 Source: DEBIAN Type: DSA-1406 horde3 -- several vulnerabilities Source: CCN Type: Horde Web site The Horde Application Framework Source: SUSE Type: UNKNOWN SUSE-SR:2006:019 Source: CCN Type: OSVDB ID: 27032 Horde go.php url Parameter XSS Source: BUGTRAQ Type: UNKNOWN 20060705 Public Advisory: Horde 3.1.1, 3.0.10 Multiple Security Issues Source: BID Type: Exploit 18845 Source: CCN Type: BID-18845 Horde Application Framework Services Multiple Cross-Site Scripting Vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2006-2694 Source: XF Type: UNKNOWN horde-tunnel-request-xss(27590) Source: SUSE Type: SUSE-SR:2006:019 SUSE Security Summary Report | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |