ubuntu · CVE-2006-4256

Quick triage

Priority: medium Published: 2006-08-21 20:04:00 UTC Updated: 2025-07-17 16:39:34 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2006-4256 medium priority: Ubuntu including 1 source packages (horde3), 9 status rows across 9 suites (dapper, edgy, feisty, gutsy, hardy, intrepid, jaunty, karmic, upstream): released 7, ignored 1, needs-triage 1.

Description:

index.php in Horde Application Framework before 3.1.2 allows remote attackers to include web pages from other sites, which could be useful for phishing attacks, via a URL in the url parameter, aka "cross-site referencing." NOTE: some sources have referred to this issue as XSS, but it is different than classic XSS.

cvelogic Threat Intelligence