PT-2006-2499 · Horde · Horde Application Framework

Jan Schneider

·

Published

2006-03-29

·

Updated

2017-07-20

·

CVE-2006-1491

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Horde Application Framework versions 3.0 through 3.0.9 Horde Application Framework versions 3.1 through 3.1.0
Description: The issue allows remote attackers to execute arbitrary code via the help viewer. This is due to an eval injection vulnerability.
Recommendations: For Horde Application Framework versions 3.0 through 3.0.9, update to version 3.0.10 or later. For Horde Application Framework versions 3.1 through 3.1.0, update to version 3.1.1 or later.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-1491
DSA-1033-1
DSA-1034-1

Affected Products

Horde Application Framework