CVE-2006-3548

UnknownEPSS 2.06%

Last modified

CVE-2006-3548 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in Horde Application Framework 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1 allow remote attackers to inject arbitrary web script or HTML via a (1) javascript URI or an external (2) http, (3) https, or (4) ftp URI in the url parameter in services/go.php (aka the dereferrer), (5) a javascript URI in the module parameter in services/help (aka the help viewer), and (6) the name parameter in services/problem.php (aka the problem reporting screen).. EPSS estimates a 2.06% chance of exploitation in the next 30 days.

Description

Multiple cross-site scripting (XSS) vulnerabilities in Horde Application Framework 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1 allow remote attackers to inject arbitrary web script or HTML via a (1) javascript URI or an external (2) http, (3) https, or (4) ftp URI in the url parameter in services/go.php (aka the dereferrer), (5) a javascript URI in the module parameter in services/help (aka the help viewer), and (6) the name parameter in services/problem.php (aka the problem reporting screen).

Metrics

EPSS Probability
2.06%

79.0th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
HordeHorde3.0
HordeHorde3.0.1
HordeHorde3.0.2
HordeHorde3.0.3
HordeHorde3.0.4
HordeHorde3.0.4_rc1
HordeHorde3.0.4_rc2
HordeHorde3.0.6
HordeHorde3.0.7
HordeHorde3.0.8
HordeHorde3.0.9
HordeHorde3.1
HordeHorde3.1.1

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2006-3548?
Multiple cross-site scripting (XSS) vulnerabilities in Horde Application Framework 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1 allow remote attackers to inject arbitrary web script or HTML via a (1) javascript URI or an external (2) http, (3) https, or (4) ftp URI in the url parameter in services/go.php (aka the dereferrer), (5) a javascript URI in the module parameter in services/help (aka the help viewer), and (6) the name parameter in services/problem.php (aka the problem reporting screen).
How severe is CVE-2006-3548?
Severity scoring for CVE-2006-3548 is pending analysis. The EPSS model estimates a 2.06% probability of exploitation in the next 30 days.
How do I fix CVE-2006-3548?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2006-3548?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST