CVE-2006-3549

Publication date 13 July 2006

Last updated 17 July 2025


Ubuntu priority

Description

services/go.php in Horde Application Framework 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1 does not properly restrict its image proxy capability, which allows remote attackers to perform "Web tunneling" attacks and use the server as a proxy via (1) http, (2) https, and (3) ftp URL in the url parameter, which is requested from the server.

Status

Package Ubuntu Release Status
horde3 9.10 karmic
Fixed 3.1.3-1
9.04 jaunty
Fixed 3.1.3-1
8.10 intrepid
Fixed 3.1.3-1
8.04 LTS hardy
Fixed 3.1.3-1
7.10 gutsy
Fixed 3.1.3-1
7.04 feisty
Fixed 3.1.3-1
6.10 edgy
Fixed 3.1.3-1
6.06 LTS dapper Ignored end of life