vendor:
Horde Groupware, Horde Groupware Webmail Edition
by:
skysbsb
7.5
CVSS
HIGH
Local File Inclusion
94
CWE
Product Name: Horde Groupware, Horde Groupware Webmail Edition
Affected Version From: Horde 3.3.2
Affected Version To: Horde 3.3.3 / 3.2.4 or later, Horde Groupware 1.2.2 / 1.1.5 or later, Horde Groupware Webmail Edition 1.2.2/1.1.5 or later
Patch Exists: YES
Related CWE: CVE-2009-0932
CPE: Horde
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=35554, https://www.infosecmatter.com/nessus-plugin-library/?id=36119, https://www.infosecmatter.com/nessus-plugin-library/?id=40961, https://www.infosecmatter.com/nessus-plugin-library/?id=36005, https://www.infosecmatter.com/nessus-plugin-library/?id=39985, https://www.infosecmatter.com/nessus-plugin-library/?id=47395
Tags: cve,cve2009,horde,lfi,traversal,edb
CVSS Metrics: CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:N
Nuclei References:
https://www.exploit-db.com/exploits/16154, http://cvs.horde.org/co.php/groupware/docs/groupware/CHANGES?r=1.28.2.5, https://nvd.nist.gov/vuln/detail/CVE-2009-0932?cpeVersion=2.2, http://cvs.horde.org/co.php/horde/docs/CHANGES?r=1.515.2.413.2.5, http://cvs.horde.org/co.php/horde/docs/CHANGES?r=1.515.2.503
Nuclei Metadata: {'max-request': 1, 'vendor': 'debian', 'product': 'horde'}
Platforms Tested: Linux
2009
Horde Horde_Image::factory driver Argument Local File Inclusion
Horde before 3.2.4 and 3.3.3 and Horde Groupware before 1.1.5 are susceptible to local file inclusion in framework/Image/Image.php because it allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Horde_Image driver name.
Mitigation:
If using Horde, upgrade to version 3.3.3 / 3.2.4 or later. If using Horde Groupware, upgrade to version 1.2.2 / 1.1.5 or later. If using Horde Groupware Webmail Edition, upgrade to version 1.2.2/1.1.5 or later.