SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-3549

services/go.php in Horde Application Framework 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1 does not properly restrict its image proxy capability, which allows remote attackers to perform "Web tunneling" attacks and use the server as a proxy via (1)…

MEDIUM 5.0EPSS 2.40%

Does this matter?

Lower severity and a low EPSS score (2.40%). Track it; it rarely justifies an emergency change on its own.

Description

services/go.php in Horde Application Framework 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1 does not properly restrict its image proxy capability, which allows remote attackers to perform "Web tunneling" attacks and use the server as a proxy via (1) http, (2) https, and (3) ftp URL in the url parameter, which is requested from the server.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
2.40% probability · 83th percentile
CISA KEV
Not listed
Affected
horde/horde application framework
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.