MEDIUM
Horde Application Framework 3.0.9 allows remote attackers to read arbitrary files via a null character in the url parameter in services/go.php, which bypasses a sanity check
Published Mar 19, 2006
5.0
MEDIUMCVSS 2.0
EPSS 12.45%
Description
Horde Application Framework 3.0.9 allows remote attackers to read arbitrary files via a null character in the url parameter in services/go.php, which bypasses a sanity check.
Affected products
No data.
OR
- 1.2
- 1.2.1
- 1.2.2
- 1.2.3
- 1.2.4
- 1.2.5
- 1.2.6
- 1.2.7
- 1.2.8
- 2.0
- 2.1
- 2.1.3
- 2.2
- 2.2.1
- 2.2.3
- 2.2.4
- 2.2.4_rc1
- 2.2.5
- 2.2.6
- 2.2.7
- 2.2.8
- 2.2.9
- 3.0
- 3.0.1
- 3.0.2
- 3.0.3
- 3.0.4
- 3.0.4_rc1
- 3.0.4_rc2
- 3.0.6
- 3.0.7
- 3.0.8
- 3.0.9
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (17)
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/043657.html mailing-listx_refsource_FULLDISCPatchVendor Advisory
- http://secunia.com/advisories/19246 third-party-advisoryx_refsource_SECUNIAExploitPatchVendor Advisory
- http://secunia.com/advisories/19528 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/19619 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/19692 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/19897 third-party-advisoryx_refsource_SECUNIA
- http://securityreason.com/securityalert/590 third-party-advisoryx_refsource_SREASON
- http://securitytracker.com/id?1015771 vdb-entryx_refsource_SECTRACKPatch
- http://www.debian.org/security/2006/dsa-1033 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2006/dsa-1034 vendor-advisoryx_refsource_DEBIAN
- http://www.gentoo.org/security/en/glsa/glsa-200604-02.xml vendor-advisoryx_refsource_GENTOO
- http://www.novell.com/linux/security/advisories/2006_04_28.html vendor-advisoryx_refsource_SUSE
- http://www.osvdb.org/23918 vdb-entryx_refsource_OSVDBExploitPatch
- http://www.securityfocus.com/archive/1/427710/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/17117 vdb-entryx_refsource_BIDPatch
- http://www.vupen.com/english/advisories/2006/0959 vdb-entryx_refsource_VUPEN
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25239 vdb-entryx_refsource_XF
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 19, 2006
Updated Aug 7, 2024
Reserved Mar 18, 2006
Link CVE-2006-1260
CISA Vulnrichment
Updated n/a