VYPR

Framework

by Horde (software)

CVEs (2)

  • CVE-2007-1473Mar 16, 2007
    risk 0.03cvss epss 0.05

    Cross-site scripting (XSS) vulnerability in framework/NLS/NLS.php in Horde Framework before 3.1.4 RC1, when the login page contains a language selection box, allows remote attackers to inject arbitrary web script or HTML via the new_lang parameter to login.php.

  • CVE-2007-6018Jan 11, 2008
    risk 0.00cvss epss 0.02

    IMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3 does not validate unspecified HTTP requests, which allows remote attackers to (1) delete arbitrary e-mail messages via a modified numeric ID or (2) "purge" deleted emails via a…