Vulnerability Name: | CVE-2006-4256 (CCN-28411) | ||||||||||||
Assigned: | 2006-08-16 | ||||||||||||
Published: | 2006-08-16 | ||||||||||||
Updated: | 2018-10-17 | ||||||||||||
Summary: | index.php in Horde Application Framework before 3.1.2 allows remote attackers to include web pages from other sites, which could be useful for phishing attacks, via a URL in the url parameter, aka "cross-site referencing." Note: some sources have referred to this issue as XSS, but it is different than classic XSS. | ||||||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
2.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
| ||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Wed Aug 16 2006 - 08:51:00 CDT [scip_Advisory 2456] Horde Framework and Horde IMP /index.php cross site referencing Source: MITRE Type: CNA CVE-2006-4256 Source: CCN Type: Horde IMP Web site IMP Webmail Client Source: MLIST Type: UNKNOWN [horde-announce] 20060817 Horde 3.1.3 (final) Source: CCN Type: SA21500 Horde Phishing and Cross-Site Scripting Vulnerabilities Source: SECUNIA Type: Vendor Advisory 21500 Source: SECUNIA Type: UNKNOWN 27565 Source: SREASON Type: UNKNOWN 1422 Source: CCN Type: SECTRACK ID: 1016713 Horde Application Framework Input Validation Holes in `index.php` and IMP`s `search.php` Permit Cross-Site Scripting Attacks Source: SECTRACK Type: UNKNOWN 1016713 Source: DEBIAN Type: UNKNOWN DSA-1406 Source: DEBIAN Type: DSA-1406 horde3 -- several vulnerabilities Source: CCN Type: Horde Application Framework Web site The Horde Application Framework Source: CCN Type: OSVDB ID: 27981 Horde search.php Multiple Field XSS Source: CCN Type: OSVDB ID: 27982 Horde index.php Cross Frame Content Loading Source: MISC Type: UNKNOWN http://www.scip.ch/cgi-bin/smss/showadvf.pl?id=2456 Source: BUGTRAQ Type: UNKNOWN 20060816 [scip_Advisory 2456] Horde Framework and Horde IMP /index.php cross site referencing Source: CCN Type: BID-19557 Horde Products GETURL Parameter Cross-Site Scripting Vulnerability Source: VUPEN Type: UNKNOWN ADV-2006-3309 Source: XF Type: UNKNOWN horde-index-xss(28411) Source: XF Type: UNKNOWN horde-index-xss(28411) | ||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |