// For flags

CVE-2008-3824

Horde Application Framework 3.2.1 - Forward Slash Insufficient Filtering Cross-Site Scripting

Severity Score

6.1
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Cross-site scripting (XSS) vulnerability in (1) Text_Filter/Filter/xss.php in Horde 3.1.x before 3.1.9 and 3.2.x before 3.2.2 and (2) externalinput.php in Popoon r22196 and earlier allows remote attackers to inject arbitrary web script or HTML by using / (slash) characters as replacements for spaces in an HTML e-mail message.

Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en (1) el módulo Text_Filter/Filter/xss.php de Horde versiones 3.1.x anteriores a 3.1.9 y versiones 3.2.x anteriores a 3.2.2 y en (2) el módulo externalinput.php de Popoon versión r22196 y anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección al reemplazar caracteres / (barra) por los espacios en blanco en un mensaje de correo electrónico en formato HTML.

The Horde project relies on code similar to Popoon's externalinput.php to filter out potential cross site scripting attacks on user-supplied input. Other projects are using the same code base. Therefore this vulnerability affects also the popular Cake-PHP framework. Hence, all users that rely on the externalinput sanitization functionality are affected by this vulnerability, as in addition to many other unrelated, open source projects.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-08-27 CVE Reserved
  • 2008-09-11 CVE Published
  • 2014-03-19 First Exploit
  • 2024-08-07 CVE Updated
  • 2025-05-28 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Horde
Search vendor "Horde"
Horde
Search vendor "Horde" for product "Horde"
3.1.1
Search vendor "Horde" for product "Horde" and version "3.1.1"
-
Affected
Horde
Search vendor "Horde"
Horde
Search vendor "Horde" for product "Horde"
3.1.2
Search vendor "Horde" for product "Horde" and version "3.1.2"
-
Affected
Horde
Search vendor "Horde"
Horde
Search vendor "Horde" for product "Horde"
3.1.3
Search vendor "Horde" for product "Horde" and version "3.1.3"
-
Affected
Horde
Search vendor "Horde"
Horde
Search vendor "Horde" for product "Horde"
3.1.4
Search vendor "Horde" for product "Horde" and version "3.1.4"
-
Affected
Horde
Search vendor "Horde"
Horde
Search vendor "Horde" for product "Horde"
3.1.5
Search vendor "Horde" for product "Horde" and version "3.1.5"
-
Affected
Horde
Search vendor "Horde"
Horde
Search vendor "Horde" for product "Horde"
3.1.6
Search vendor "Horde" for product "Horde" and version "3.1.6"
-
Affected
Horde
Search vendor "Horde"
Horde
Search vendor "Horde" for product "Horde"
3.1.7
Search vendor "Horde" for product "Horde" and version "3.1.7"
-
Affected
Horde
Search vendor "Horde"
Horde
Search vendor "Horde" for product "Horde"
3.1.8
Search vendor "Horde" for product "Horde" and version "3.1.8"
-
Affected
Horde
Search vendor "Horde"
Horde
Search vendor "Horde" for product "Horde"
3.2
Search vendor "Horde" for product "Horde" and version "3.2"
-
Affected
Horde
Search vendor "Horde"
Horde
Search vendor "Horde" for product "Horde"
3.2.1
Search vendor "Horde" for product "Horde" and version "3.2.1"
-
Affected
Popoon
Search vendor "Popoon"
Popoon
Search vendor "Popoon" for product "Popoon"
<= r22196
Search vendor "Popoon" for product "Popoon" and version " <= r22196"
-
Affected