CVE-2006-4256
Last modified
CVE-2006-4256 is a vulnerability of currently unknown severity. index.php in Horde Application Framework before 3.1.2 allows remote attackers to include web pages from other sites, which could be useful for phishing attacks, via a URL in the url parameter, aka "cross-site referencing." NOTE: some sources have referred to this issue as XSS, but it is different than classic XSS.. EPSS estimates a 1.67% chance of exploitation in the next 30 days.
Description
index.php in Horde Application Framework before 3.1.2 allows remote attackers to include web pages from other sites, which could be useful for phishing attacks, via a URL in the url parameter, aka "cross-site referencing." NOTE: some sources have referred to this issue as XSS, but it is different than classic XSS.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Horde | Application Framework | 3.0 |
| Horde | Application Framework | 3.0.1 |
| Horde | Application Framework | 3.0.2 |
| Horde | Application Framework | 3.0.3 |
| Horde | Application Framework | 3.0.4 |
| Horde | Application Framework | 3.0.4_rc1 |
| Horde | Application Framework | 3.0.4_rc2 |
| Horde | Application Framework | 3.0.6 |
| Horde | Application Framework | 3.0.7 |
| Horde | Application Framework | 3.0.8 |
| Horde | Application Framework | 3.0.9 |
| Horde | Application Framework | 3.1 |
| Horde | Application Framework | 3.1.1 |
References
- http://secunia.com/advisories/21500Vendor Advisory
- http://secunia.com/advisories/21500Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-4256?
How severe is CVE-2006-4256?
How do I fix CVE-2006-4256?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-4250Buffer overflow in man and mandb (man-db) 2.4.3 and earlier …
- CVE-2006-4251Buffer overflow in PowerDNS Recursor 3.1.3 and earlier might…
- CVE-2006-4252PowerDNS Recursor 3.1.3 and earlier allows remote attackers …
- CVE-2006-4253Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and ear…
- CVE-2006-4254Unspecified vulnerability in setlocale in IBM AIX 5.1.0 thro…
- CVE-2006-4255Cross-site scripting (XSS) vulnerability in horde/imp/search…
- CVE-2006-4257IBM DB2 Universal Database (UDB) before 8.1 FixPak 13 allows…
- CVE-2006-4258Absolute path traversal vulnerability in the get functionali…
- CVE-2006-4259Cross-site scripting (XSS) vulnerability in index.php in Fot…
- CVE-2006-4260Directory traversal vulnerability in index.php in Fotopholde…
- CVE-2006-4261Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2006-4262Multiple buffer overflows in cscope 15.5 and earlier allow u…
Are you affected by CVE-2006-4256?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
