CVE Database
/

CVE-2006-4256

Back to search

CVE-2006-4256

Published: Aug 21, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

index.php in Horde Application Framework before 3.1.2 allows remote attackers to include web pages from other sites, which could be useful for phishing attacks, via a URL in the url parameter, aka "cross-site referencing." NOTE: some sources have referred to this issue as XSS, but it is different than classic XSS.

VendorProductVersions

n/a

n/a

affected
n/a

References

27565
third-party-advisory
x_refsource_SECUNIA
1422
third-party-advisory
x_refsource_SREASON
21500
third-party-advisory
x_refsource_SECUNIA
ADV-2006-3309
vdb-entry
x_refsource_VUPEN
DSA-1406
vendor-advisory
x_refsource_DEBIAN
horde-index-xss(28411)
vdb-entry
x_refsource_XF
1016713
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now