Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2010-3077Cross-site Scripting in Application Framework

Severity
4.3MEDIUMNVD
EPSS
0.7%
top 27.13%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedNov 9
Latest updateMay 17

Description

Cross-site scripting (XSS) vulnerability in util/icon_browser.php in the Horde Application Framework before 3.3.9 allows remote attackers to inject arbitrary web script or HTML via the subdir parameter.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-wv2h-929x-6v2j: Cross-site scripting (XSS) vulnerability in util/icon_browser2022-05-17

💥Exploits & PoCs

1
Exploit-DB
Horde Application Framework 3.3.8 - 'icon_browser.php' Cross-Site Scripting2010-09-06

💬Community

2
Bugzilla
CVE-2010-3077 CVE-2010-3694 Horde: multiple flaws correct in 3.3.9 [fedora-all]2010-09-06
Bugzilla
CVE-2010-3077 CVE-2010-3694 Horde: multiple flaws correct in 3.3.92010-09-06