PT-2006-6806 · Horde · Horde Kronolith H3
Published
2006-11-30
·
Updated
2016-10-18
·
CVE-2006-6175
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Horde Kronolith H3 versions 2.0.0 through 2.0.6
Horde Kronolith H3 version 2.1.x prior to 2.1.4
Description
The issue allows remote attackers to include arbitrary files and execute PHP code via a .. (dot dot) sequence in the
view parameter. This is a directory traversal vulnerability in the lib/FBView.php file.Recommendations
For Horde Kronolith H3 versions 2.0.0 through 2.0.6, update to version 2.0.7 or later.
For Horde Kronolith H3 version 2.1.x prior to 2.1.4, update to version 2.1.4 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Horde Kronolith H3