Candidate: CVE-2010-3077 PublicDate: 2010-11-09 21:00:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3077 Description: Cross-site scripting (XSS) vulnerability in util/icon_browser.php in the Horde Application Framework before 3.3.9 allows remote attackers to inject arbitrary web script or HTML via the subdir parameter. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_horde3: upstream_horde3: released (3.3.9) dapper_horde3: ignored (reached end-of-life) hardy_horde3: ignored (reached end-of-life) karmic_horde3: ignored (reached end-of-life) lucid_horde3: ignored (reached end-of-life) maverick_horde3: ignored (reached end-of-life) natty_horde3: not-affected (3.3.8+debian0-2) oneiric_horde3: not-affected (3.3.8+debian0-2) precise_horde3: not-affected (3.3.8+debian0-2) quantal_horde3: not-affected (3.3.8+debian0-2) raring_horde3: not-affected (3.3.8+debian0-2) saucy_horde3: not-affected (3.3.8+debian0-2) devel_horde3: DNE