CVE-2008-3824
Horde Application Framework 3.2.1 - Forward Slash Insufficient Filtering Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in (1) Text_Filter/Filter/xss.php in Horde 3.1.x before 3.1.9 and 3.2.x before 3.2.2 and (2) externalinput.php in Popoon r22196 and earlier allows remote attackers to inject arbitrary web script or HTML by using / (slash) characters as replacements for spaces in an HTML e-mail message.
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en (1) el módulo Text_Filter/Filter/xss.php de Horde versiones 3.1.x anteriores a 3.1.9 y versiones 3.2.x anteriores a 3.2.2 y en (2) el módulo externalinput.php de Popoon versión r22196 y anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección al reemplazar caracteres / (barra) por los espacios en blanco en un mensaje de correo electrónico en formato HTML.
The Horde project relies on code similar to Popoon's externalinput.php to filter out potential cross site scripting attacks on user-supplied input. Other projects are using the same code base. Therefore this vulnerability affects also the popular Cake-PHP framework. Hence, all users that rely on the externalinput sanitization functionality are affected by this vulnerability, as in addition to many other unrelated, open source projects.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-08-27 CVE Reserved
- 2008-09-11 CVE Published
- 2014-03-19 First Exploit
- 2024-08-07 CVE Updated
- 2025-05-28 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (16)
URL | Tag | Source |
---|---|---|
http://blog.liip.ch/missed-case-in-externalinput-php-resulting-in-viable-xss-attacks.html | X_refsource_confirm | |
http://marc.info/?l=horde-announce&m=122104360019867&w=2 | Mailing List | |
http://osvdb.org/47996 | Vdb Entry | |
http://securityreason.com/securityalert/4245 | Third Party Advisory | |
http://www.openwall.com/lists/oss-security/2008/09/10/1 | Mailing List |
|
http://www.phpmyfaq.de/advisory_2008-09-11.php | X_refsource_confirm | |
http://www.securityfocus.com/archive/1/496182/100/0/threaded | Mailing List | |
http://www.vupen.com/english/advisories/2008/2548 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/45031 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/32353 | 2014-03-19 | |
http://www.securityfocus.com/bid/31107 | 2024-08-07 |
URL | Date | SRC |
---|---|---|
http://marc.info/?l=horde-announce&m=122103888111491&w=2 | 2018-10-11 | |
http://ocert.org/patches/2008-012/Text_Filter.31.patch | 2018-10-11 | |
http://ocert.org/patches/2008-012/Text_Filter.patch | 2018-10-11 | |
http://www.ocert.org/advisories/ocert-2008-012.html | 2018-10-11 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/31842 | 2018-10-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Horde Search vendor "Horde" | Horde Search vendor "Horde" for product "Horde" | 3.1.1 Search vendor "Horde" for product "Horde" and version "3.1.1" | - |
Affected
| ||||||
Horde Search vendor "Horde" | Horde Search vendor "Horde" for product "Horde" | 3.1.2 Search vendor "Horde" for product "Horde" and version "3.1.2" | - |
Affected
| ||||||
Horde Search vendor "Horde" | Horde Search vendor "Horde" for product "Horde" | 3.1.3 Search vendor "Horde" for product "Horde" and version "3.1.3" | - |
Affected
| ||||||
Horde Search vendor "Horde" | Horde Search vendor "Horde" for product "Horde" | 3.1.4 Search vendor "Horde" for product "Horde" and version "3.1.4" | - |
Affected
| ||||||
Horde Search vendor "Horde" | Horde Search vendor "Horde" for product "Horde" | 3.1.5 Search vendor "Horde" for product "Horde" and version "3.1.5" | - |
Affected
| ||||||
Horde Search vendor "Horde" | Horde Search vendor "Horde" for product "Horde" | 3.1.6 Search vendor "Horde" for product "Horde" and version "3.1.6" | - |
Affected
| ||||||
Horde Search vendor "Horde" | Horde Search vendor "Horde" for product "Horde" | 3.1.7 Search vendor "Horde" for product "Horde" and version "3.1.7" | - |
Affected
| ||||||
Horde Search vendor "Horde" | Horde Search vendor "Horde" for product "Horde" | 3.1.8 Search vendor "Horde" for product "Horde" and version "3.1.8" | - |
Affected
| ||||||
Horde Search vendor "Horde" | Horde Search vendor "Horde" for product "Horde" | 3.2 Search vendor "Horde" for product "Horde" and version "3.2" | - |
Affected
| ||||||
Horde Search vendor "Horde" | Horde Search vendor "Horde" for product "Horde" | 3.2.1 Search vendor "Horde" for product "Horde" and version "3.2.1" | - |
Affected
| ||||||
Popoon Search vendor "Popoon" | Popoon Search vendor "Popoon" for product "Popoon" | <= r22196 Search vendor "Popoon" for product "Popoon" and version " <= r22196" | - |
Affected
|