CVE-2006-4256
Estado: ModificadaMedia (4.3)—
index.php in Horde Application Framework before 3.1.2 allows remote attackers to include web pages from other sites, which could be useful for phishing attacks, via a URL in the url parameter, aka "cross-site referencing." NOTE: some sources have referred to this issue as XSS, but it is different than classic XSS.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.76%
- Percentil entre todas las CVEs puntuadas: 77
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://lists.horde.org/archives/announce/2006/000292.html
- http://secunia.com/advisories/21500
- http://secunia.com/advisories/27565
- http://securityreason.com/securityalert/1422
- http://securitytracker.com/id?1016713
- http://www.debian.org/security/2007/dsa-1406
- http://www.scip.ch/cgi-bin/smss/showadvf.pl?id=2456
- http://www.securityfocus.com/archive/1/443360/100/0/threaded
- http://www.vupen.com/english/advisories/2006/3309
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28411
- http://lists.horde.org/archives/announce/2006/000292.html
- http://secunia.com/advisories/21500
- http://secunia.com/advisories/27565
- http://securityreason.com/securityalert/1422
- http://securitytracker.com/id?1016713
- http://www.debian.org/security/2007/dsa-1406
- http://www.scip.ch/cgi-bin/smss/showadvf.pl?id=2456
- http://www.securityfocus.com/archive/1/443360/100/0/threaded
- http://www.vupen.com/english/advisories/2006/3309
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28411
JSON original (NVD)
Mostrar
{
"id": "CVE-2006-4256",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-08-21T20:04:00.000",
"references": [
{
"url": "http://lists.horde.org/archives/announce/2006/000292.html",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/21500",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/27565",
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/1422",
"source": "cve@mitre.org"
},
{
"url": "http://securitytracker.com/id?1016713",
"source": "cve@mitre.org"
},
{
"url": "http://www.debian.org/security/2007/dsa-1406",
"source": "cve@mitre.org"
},
{
"url": "http://www.scip.ch/cgi-bin/smss/showadvf.pl?id=2456",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/443360/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2006/3309",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/28411",
"source": "cve@mitre.org"
},
{
"url": "http://lists.horde.org/archives/announce/2006/000292.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/21500",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/27565",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/1422",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securitytracker.com/id?1016713",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.debian.org/security/2007/dsa-1406",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.scip.ch/cgi-bin/smss/showadvf.pl?id=2456",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/443360/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2006/3309",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/28411",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "index.php in Horde Application Framework before 3.1.2 allows remote attackers to include web pages from other sites, which could be useful for phishing attacks, via a URL in the url parameter, aka \"cross-site referencing.\" NOTE: some sources have referred to this issue as XSS, but it is different than classic XSS."
},
{
"lang": "es",
"value": "index.php en Horde Application Framework anerior a 3.1.2 permite a atacantes remotos incluir páginas web de otros sitios, lo que podría ser útil para ataques de phishing, mediante una URL en el parámetro url, también conocido como \"referencia en sitios cruzados\" (cross-site referencing). NOTA: algunas fuetnes se han referido a este problema como XSS, pero es diferente del clásico XSS."
}
],
"lastModified": "2026-06-16T22:28:43.900",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:horde:application_framework:3.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CEC8BBFC-263E-4735-847D-5544D18922E4"
},
{
"criteria": "cpe:2.3:a:horde:application_framework:3.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8DB1F389-5D64-4B8C-B207-7D23F0C12DBE"
},
{
"criteria": "cpe:2.3:a:horde:application_framework:3.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BE8892DF-11F2-4991-97E8-D561DEAC4F5B"
},
{
"criteria": "cpe:2.3:a:horde:application_framework:3.0.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3B46B6F5-055E-44EB-BB78-503811C0E57C"
},
{
"criteria": "cpe:2.3:a:horde:application_framework:3.0.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "66B197B0-F3B7-40D6-9872-C1A94622C242"
},
{
"criteria": "cpe:2.3:a:horde:application_framework:3.0.4_rc1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BAEAAF02-1B61-421A-887C-107B7234262B"
},
{
"criteria": "cpe:2.3:a:horde:application_framework:3.0.4_rc2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "01557585-CE92-49FB-B9BB-AAAE7D355BE9"
},
{
"criteria": "cpe:2.3:a:horde:application_framework:3.0.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2698E2D7-09BF-4490-B362-4245CD3087D1"
},
{
"criteria": "cpe:2.3:a:horde:application_framework:3.0.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A3B40A46-117D-4D85-8CC8-27236A3280C0"
},
{
"criteria": "cpe:2.3:a:horde:application_framework:3.0.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FEFBECFF-D1A4-465D-B59F-E70246DE4BE7"
},
{
"criteria": "cpe:2.3:a:horde:application_framework:3.0.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "57ABD1BD-6676-4B54-9F3E-FACF1346794F"
},
{
"criteria": "cpe:2.3:a:horde:application_framework:3.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "79EC6167-5D16-4236-8EBC-412EE1784802"
},
{
"criteria": "cpe:2.3:a:horde:application_framework:3.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5A4F6A2A-05B6-42EA-8F61-D0AB610A6757"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}