Cross-site scripting (XSS) vulnerability in horde 3 (horde3) before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via (1) templates/problem/problem.inc and (2) test.php. This vulnerability is addressed in the following product release:
Horde, Horde, 3.1.1
Publication date: Thu, 15 Jun 2006 15:02:00 +0000