PT-2009-3518 · Horde · Horde Groupware+1

Gunnar Wrobel

·

Publicado

2009-03-17

·

Atualizado

2011-09-22

·

CVE-2009-0932

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Horde versions prior to 3.2.4 Horde versions prior to 3.3.3 Horde Groupware versions prior to 1.1.5
Description The issue allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Horde Image driver name. This is a directory traversal vulnerability in the framework/Image/Image.php file.
Recommendations For Horde versions prior to 3.2.4, update to version 3.2.4 or later. For Horde versions prior to 3.3.3, update to version 3.3.3 or later. For Horde Groupware versions prior to 1.1.5, update to version 1.1.5 or later.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-0932
DSA-1765-1

Produtos afetados

Horde
Horde Groupware