Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in Horde Application Framework 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1 allow remote attackers to inject arbitrary web script or HTML via a (1) javascript URI or an external (2) http, (3) https, or (4) ftp URI in the url parameter in services/go.php (aka the dereferrer), (5) a javascript URI in the module parameter in services/help (aka the help viewer), and (6) the name parameter in services/problem.php (aka the problem reporting screen).
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Horde Application Framework Services多个跨站脚本攻击漏洞
Vulnerability Description
Horde Application Framework 3.0.0到3.0.10 和 3.1.0到3.1.1存在多个跨站脚本攻击(XSS) 漏洞。远程攻击者可以借助services/go.php (又称dereferrer)中的url 参数中的 (1) javascript URI或外部(2) http, (3) https,或(4) ftp URI , (5) services/help (又称help viewer)中的module参数的 javascript URI , 以及 (6)services
CVSS Information
N/A
Vulnerability Type
N/A