PT-2009-3518 · Horde · Horde Groupware+1

Gunnar Wrobel

·

Published

2009-03-17

·

Updated

2011-09-22

·

CVE-2009-0932

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Horde versions prior to 3.2.4 Horde versions prior to 3.3.3 Horde Groupware versions prior to 1.1.5
Description The issue allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Horde Image driver name. This is a directory traversal vulnerability in the framework/Image/Image.php file.
Recommendations For Horde versions prior to 3.2.4, update to version 3.2.4 or later. For Horde versions prior to 3.3.3, update to version 3.3.3 or later. For Horde Groupware versions prior to 1.1.5, update to version 1.1.5 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-0932
DSA-1765-1

Affected Products

Horde
Horde Groupware