6.8
CVSSv2

CVE-2007-1474

Published: 16/03/2007 Updated: 29/07/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows local users to delete arbitrary files and possibly gain privileges via multiple space-delimited pathnames.

Vulnerable Product Search on Vulmon Subscribe to Product

horde horde application framework 3.0.4

horde horde application framework 3.1.3

horde imp 2.2.5

horde imp 2.2.6

horde imp 3.2.1

horde imp 3.2.2

horde imp 2.0

horde imp 2.2

horde imp 2.2.7

horde imp 2.2.8

horde imp 3.2.3

horde imp 3.2.4

horde horde application framework 3.0.0

horde imp 2.2.3

horde imp 2.2.4

horde imp 3.1.2

horde imp 3.2

horde imp 2.2.1

horde imp 2.2.2

horde imp 2.3

horde imp 3.0

horde imp 3.1

horde imp 3.2.5

horde imp 3.2.6

Vendor Advisories

Several remote vulnerabilities have been discovered in the Horde web application framework The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2006-3548 Moritz Naumann discovered that Horde allows remote attackers to inject arbitrary web script or HTML in the context of a logged in user (cross ...

Exploits

source: wwwsecurityfocuscom/bid/22985/info Horde Framework and IMP are prone to a vulnerability that allows a local attacker to delete arbitrary files in the context of the user running the application A successful attack can reduce the integrity of affected computers and may aid in further attacks An attacker could exploit this issu ...