PT-2014-4294 · Horde · Horde

João Machado

·

Publicado

2014-04-01

·

Atualizado

2014-04-02

·

CVE-2014-1691

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Horde versions prior to 5.1.1
Description The issue allows remote attackers to conduct object injection attacks and execute arbitrary PHP code via a crafted serialized object in the formvars form. This is due to a vulnerability in the Variables.php script within the Util library.
Recommendations For versions prior to 5.1.1, update to version 5.1.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the Variables.php script to minimize the risk of exploitation.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-1691
DSA-2853-1

Produtos afetados

Horde