CVE-2006-3549
Summary
| CVE | CVE-2006-3549 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-07-13 00:05:00 UTC |
| Updated | 2018-10-18 16:47:00 UTC |
| Description | services/go.php in Horde Application Framework 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1 does not properly restrict its image proxy capability, which allows remote attackers to perform "Web tunneling" attacks and use the server as a proxy via (1) http, (2) https, and (3) ftp URL in the url parameter, which is requested from the server. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Horde | Horde Application Framework | 3.0.0 | All | All | All |
| Application | Horde | Horde Application Framework | 3.0.1 | All | All | All |
| Application | Horde | Horde Application Framework | 3.0.10 | All | All | All |
| Application | Horde | Horde Application Framework | 3.0.2 | All | All | All |
| Application | Horde | Horde Application Framework | 3.0.3 | All | All | All |
| Application | Horde | Horde Application Framework | 3.0.4 | All | All | All |
| Application | Horde | Horde Application Framework | 3.0.5 | All | All | All |
| Application | Horde | Horde Application Framework | 3.0.6 | All | All | All |
| Application | Horde | Horde Application Framework | 3.0.7 | All | All | All |
| Application | Horde | Horde Application Framework | 3.0.8 | All | All | All |
| Application | Horde | Horde Application Framework | 3.0.9 | All | All | All |
| Application | Horde | Horde Application Framework | 3.1.0 | All | All | All |
| Application | Horde | Horde Application Framework | 3.1.1 | All | All | All |
| Application | Horde | Horde Application Framework | 3.0.0 | All | All | All |
| Application | Horde | Horde Application Framework | 3.0.1 | All | All | All |
| Application | Horde | Horde Application Framework | 3.0.10 | All | All | All |
| Application | Horde | Horde Application Framework | 3.0.2 | All | All | All |
| Application | Horde | Horde Application Framework | 3.0.3 | All | All | All |
| Application | Horde | Horde Application Framework | 3.0.4 | All | All | All |
| Application | Horde | Horde Application Framework | 3.0.5 | All | All | All |
| Application | Horde | Horde Application Framework | 3.0.6 | All | All | All |
| Application | Horde | Horde Application Framework | 3.0.7 | All | All | All |
| Application | Horde | Horde Application Framework | 3.0.8 | All | All | All |
| Application | Horde | Horde Application Framework | 3.0.9 | All | All | All |
| Application | Horde | Horde Application Framework | 3.1.0 | All | All | All |
| Application | Horde | Horde Application Framework | 3.1.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Error 403 - Forbidden | MISC | moritz-naumann.com | Exploit |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| [announce] Horde 3.1.2 (final) | CONFIRM | lists.horde.org | |
| Debian update for horde3 - Advisories - Secunia | SECUNIA | secunia.com | |
| Horde 3.1.1, 3.0.10 Multiple Security Issues - CXSecurity.com | SREASON | securityreason.com | |
| SecurityTracker.com Archives - Horde Application Framework Input Validation Hole Permits Cross-Site Scripting Attacks | SECTRACK | securitytracker.com | Exploit |
| SUSE Updates for Multiple Packages - Advisories - Secunia | SECUNIA | secunia.com | |
| Horde Cross-Site Scripting Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | |
| Horde Application Framework Services Multiple Cross-Site Scripting Vulnerabilities | BID | www.securityfocus.com | Exploit |
| [announce] Horde 3.0.11 (final) | CONFIRM | lists.horde.org | Patch |
| Security Announcement | SUSE | www.novell.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Debian -- Security Information -- DSA-1406-1 horde3 | DEBIAN | www.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.