PT-2006-5067 · Horde · Horde Application Framework

Marc Ruef

·

Publicado

2006-08-21

·

Atualizado

2018-10-17

·

CVE-2006-4256

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Horde Application Framework versions prior to 3.1.2
Description The issue allows remote attackers to include web pages from other sites via a URL in the url parameter, which could be useful for phishing attacks. This is sometimes referred to as "cross-site referencing," distinct from classic cross-site scripting (XSS).
Recommendations For versions prior to 3.1.2, update to version 3.1.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the index.php file or validating and sanitizing the url parameter to prevent malicious inclusion of external web pages.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-4256
DSA-1406-1

Produtos afetados

Horde Application Framework