PT-2004-3630 · Horde · Horde Application Framework
Publicado
2004-12-31
·
Atualizado
2017-07-29
·
CVE-2004-2741
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Horde Application Framework version 2.2.6
Description
The issue is related to a cross-site scripting (XSS) vulnerability in the "help window" (help.php) that allows remote attackers to inject arbitrary web script or HTML. This can be achieved via the
module, topic, or module parameters.Recommendations
For Horde Application Framework version 2.2.6, consider disabling the "help window" (help.php) until a patch is available to prevent exploitation. Restrict access to the vulnerable parameters
module, topic, to minimize the risk of XSS attacks.Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Horde Application Framework