CVE-2009-3701
Summary
| CVE | CVE-2009-3701 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-12-21 16:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in Horde Application Framework before 3.3.6, Horde Groupware before 1.2.5, and Horde Groupware Webmail Edition before 1.2.5 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) phpshell.php, (2) cmdshell.php, or (3) sqlshell.php in admin/, related to the PHP_SELF variable. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Horde | Application Framework | 2.0 | All | All | All |
| Application | Horde | Application Framework | 2.1 | All | All | All |
| Application | Horde | Application Framework | 2.1.3 | All | All | All |
| Application | Horde | Application Framework | 2.2 | All | All | All |
| Application | Horde | Application Framework | 2.2.1 | All | All | All |
| Application | Horde | Application Framework | 2.2.3 | All | All | All |
| Application | Horde | Application Framework | 2.2.4 | All | All | All |
| Application | Horde | Application Framework | 2.2.4_rc1 | All | All | All |
| Application | Horde | Application Framework | 2.2.5 | All | All | All |
| Application | Horde | Application Framework | 2.2.6 | All | All | All |
| Application | Horde | Application Framework | 3.0 | All | All | All |
| Application | Horde | Application Framework | 3.0.1 | All | All | All |
| Application | Horde | Application Framework | 3.0.2 | All | All | All |
| Application | Horde | Application Framework | 3.0.3 | All | All | All |
| Application | Horde | Application Framework | 3.0.4 | All | All | All |
| Application | Horde | Application Framework | 3.0.6 | All | All | All |
| Application | Horde | Application Framework | 3.0.7 | All | All | All |
| Application | Horde | Application Framework | 3.0.8 | All | All | All |
| Application | Horde | Application Framework | 3.0.9 | All | All | All |
| Application | Horde | Application Framework | 3.1 | All | All | All |
| Application | Horde | Application Framework | 3.1.1 | All | All | All |
| Application | Horde | Application Framework | 3.2 | All | All | All |
| Application | Horde | Application Framework | 3.2.1 | All | All | All |
| Application | Horde | Application Framework | 3.2.2 | All | All | All |
| Application | Horde | Application Framework | 3.2.3 | All | All | All |
| Application | Horde | Application Framework | 3.2.4 | All | All | All |
| Application | Horde | Application Framework | 3.3 | All | All | All |
| Application | Horde | Application Framework | 3.3.1 | All | All | All |
| Application | Horde | Application Framework | 3.3.2 | All | All | All |
| Application | Horde | Application Framework | 3.3.3 | All | All | All |
| Application | Horde | Application Framework | 3.3.4 | All | All | All |
| Application | Horde | Application Framework | All | All | All | All |
| Application | Horde | Groupware | 1.0 | All | All | All |
| Application | Horde | Groupware | 1.0.1 | All | All | All |
| Application | Horde | Groupware | 1.0.2 | All | All | All |
| Application | Horde | Groupware | 1.0.3 | All | All | All |
| Application | Horde | Groupware | 1.0.4 | All | All | All |
| Application | Horde | Groupware | 1.0.5 | All | All | All |
| Application | Horde | Groupware | 1.1 | All | All | All |
| Application | Horde | Groupware | 1.1.1 | All | All | All |
| Application | Horde | Groupware | 1.1.2 | All | All | All |
| Application | Horde | Groupware | 1.1.3 | All | All | All |
| Application | Horde | Groupware | 1.1.4 | All | All | All |
| Application | Horde | Groupware | 1.1.5 | All | All | All |
| Application | Horde | Groupware | 1.2 | All | All | All |
| Application | Horde | Groupware | 1.2 | rc1 | All | All |
| Application | Horde | Groupware | 1.2.1 | All | All | All |
| Application | Horde | Groupware | 1.2.2 | All | All | All |
| Application | Horde | Groupware | 1.2.3 | All | All | All |
| Application | Horde | Groupware | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| '[announce] Horde Groupware 1.2.5 (final)' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| SecurityTracker.com Archives - Horde Application Framework Input Validation Flaw in Administrator Scripts Permits Cross-Site Scripting Attacks | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Patch, Vendor Advisory |
| archives.neohapsis.com/archives/fulldisclosure/2009-12/0388.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | Exploit |
| Webmail- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Patch, Vendor Advisory |
| [announce] Horde 3.3.6 (final) | af854a3a-2127-422b-91ae-364da2661108 | lists.horde.org | Patch |
| '[announce] Horde Groupware Webmail Edition 1.2.5 (final)' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Patch |
| Horde Application Framework Cross-Site Scripting Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Horde Groupware / Groupware Webmail Edition "PHP_SELF" Cross-Site Scripting - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Horde Application Framework Administration Interface 'PHP_SELF' Cross-Site Scripting Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| Version Control :: Diff for horde/docs/CHANGES between version 1.515.2.559 and 1.515.2.589 | af854a3a-2127-422b-91ae-364da2661108 | cvs.horde.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.