« Volver al listado

CVE-2006-4256

Estado: ModificadaMedia (4.3)—

index.php in Horde Application Framework before 3.1.2 allows remote attackers to include web pages from other sites, which could be useful for phishing attacks, via a URL in the url parameter, aka "cross-site referencing." NOTE: some sources have referred to this issue as XSS, but it is different than classic XSS.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-4256",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2006-08-21T20:04:00.000",
  "references": [
    {
      "url": "http://lists.horde.org/archives/announce/2006/000292.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/21500",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/27565",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securityreason.com/securityalert/1422",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securitytracker.com/id?1016713",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.debian.org/security/2007/dsa-1406",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.scip.ch/cgi-bin/smss/showadvf.pl?id=2456",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/443360/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/3309",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/28411",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://lists.horde.org/archives/announce/2006/000292.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/21500",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/27565",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securityreason.com/securityalert/1422",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securitytracker.com/id?1016713",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.debian.org/security/2007/dsa-1406",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.scip.ch/cgi-bin/smss/showadvf.pl?id=2456",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/443360/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/3309",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/28411",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "index.php in Horde Application Framework before 3.1.2 allows remote attackers to include web pages from other sites, which could be useful for phishing attacks, via a URL in the url parameter, aka \"cross-site referencing.\" NOTE: some sources have referred to this issue as XSS, but it is different than classic XSS."
    },
    {
      "lang": "es",
      "value": "index.php en Horde Application Framework anerior a 3.1.2 permite a atacantes remotos incluir páginas web de otros sitios, lo que podría ser útil para ataques de phishing, mediante una URL en el parámetro url, también conocido como \"referencia en sitios cruzados\" (cross-site referencing). NOTA: algunas fuetnes se han referido a este problema como XSS, pero es diferente del clásico XSS."
    }
  ],
  "lastModified": "2026-06-16T22:28:43.900",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:horde:application_framework:3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CEC8BBFC-263E-4735-847D-5544D18922E4"
            },
            {
              "criteria": "cpe:2.3:a:horde:application_framework:3.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8DB1F389-5D64-4B8C-B207-7D23F0C12DBE"
            },
            {
              "criteria": "cpe:2.3:a:horde:application_framework:3.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BE8892DF-11F2-4991-97E8-D561DEAC4F5B"
            },
            {
              "criteria": "cpe:2.3:a:horde:application_framework:3.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3B46B6F5-055E-44EB-BB78-503811C0E57C"
            },
            {
              "criteria": "cpe:2.3:a:horde:application_framework:3.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "66B197B0-F3B7-40D6-9872-C1A94622C242"
            },
            {
              "criteria": "cpe:2.3:a:horde:application_framework:3.0.4_rc1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BAEAAF02-1B61-421A-887C-107B7234262B"
            },
            {
              "criteria": "cpe:2.3:a:horde:application_framework:3.0.4_rc2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "01557585-CE92-49FB-B9BB-AAAE7D355BE9"
            },
            {
              "criteria": "cpe:2.3:a:horde:application_framework:3.0.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2698E2D7-09BF-4490-B362-4245CD3087D1"
            },
            {
              "criteria": "cpe:2.3:a:horde:application_framework:3.0.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A3B40A46-117D-4D85-8CC8-27236A3280C0"
            },
            {
              "criteria": "cpe:2.3:a:horde:application_framework:3.0.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FEFBECFF-D1A4-465D-B59F-E70246DE4BE7"
            },
            {
              "criteria": "cpe:2.3:a:horde:application_framework:3.0.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "57ABD1BD-6676-4B54-9F3E-FACF1346794F"
            },
            {
              "criteria": "cpe:2.3:a:horde:application_framework:3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "79EC6167-5D16-4236-8EBC-412EE1784802"
            },
            {
              "criteria": "cpe:2.3:a:horde:application_framework:3.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A4F6A2A-05B6-42EA-8F61-D0AB610A6757"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}