CVE-2009-3701 | Horde Application Framework up to 3.0.7 Administration Interface phpshell.php PHP_SELF cross site scripting (EDB-10512 / Nessus ID 44831)
A vulnerability has been found in Horde Application Framework up to 3.0.7 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file phpshell.php of the component Administration Interface. The manipulation of the argument PHP_SELF leads to cross site scripting.
This vulnerability is known as CVE-2009-3701. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.