VDB
CVE-2010-3077
CVE-2010-3077
PUBLISHED
CVSS 4.300000190734863 MEDIUM
Cross-site scripting (XSS) vulnerability in util/icon_browser.php in the Horde Application Framework before 3.3.9 allows remote attackers to inject arbitrary web script or HTML via the subdir parameter.
EPSS 0.74% · 73.2th percentile
Risk Scores
CVSS 2.0
4.300000190734863
EPSS Score
0.74%
73.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| horde | horde_application_framework | 2.2.9, 0, 1.0.3 |
| n/a | n/a | n/a |
Timeline
- Nov 9, 2010 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- http://secunia.com/advisories/42140 technical
- https://bugzilla.redhat.com/show_bug.cgi?id=630687 url
- 20100906 XSS in Horde Application Framework <=3.3.8, icon_browser.php mailing-list
- FEDORA-2010-16592 vendor-advisory
- http://git.horde.org/diff.php/horde/util/icon_browser.php?rt=horde-git&r1=a978a35c3e95e784253508fd4333d2fbb64830b6&r2=9342addbd2b95f184f230773daa4faf5ef6d65e9 url
- FEDORA-2010-16555 vendor-advisory
- [announce] 20100928 Horde 3.3.9 (final) mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2010-3077 advisory