Arbitrary Code Injection in Horde Application Framework 2.2.6 help window (help.php)

Arbitrary Code Injection in Horde Application Framework 2.2.6 help window (help.php)

CVE-2004-2741 · MEDIUM Severity

AV:N/AC:M/AU:N/C:N/I:P/A:N

Cross-site scripting (XSS) vulnerability in the "help window" (help.php) in Horde Application Framework 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) module, (2) topic, or (3) module parameters.

Learn more about our Web App Pen Testing.