CVE-2006-3549: Medium severity Horde Horde Application Framework vulnerability
services/go.php in Horde Application Framework 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1 does not properly restrict its image proxy capability, which allows remote attackers to perform "Web tunneling" attacks and use the server as a proxy via (1) http, (2) https, and (3) ftp URL in the url parameter, which is requested from the server.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3549?
CVE-2006-3549 is considered a high severity vulnerability due to its ability to allow remote attackers to exploit the image proxy of the Horde Application Framework.
How do I fix CVE-2006-3549?
To fix CVE-2006-3549, you should upgrade to Horde Application Framework version 3.1.2 or later, which addresses this vulnerability.
What versions of Horde Application Framework are affected by CVE-2006-3549?
CVE-2006-3549 affects Horde Application Framework versions 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1.
What type of attack is enabled by CVE-2006-3549?
CVE-2006-3549 enables remote attackers to perform 'Web tunneling' attacks, effectively using the server as a proxy.
Is CVE-2006-3549 remotely exploitable?
Yes, CVE-2006-3549 is remotely exploitable, allowing attackers to manipulate the image proxy feature from outside the local network.