6
CVSSv2

CVE-2008-1284

Published: 11/03/2008 Updated: 11/10/2018
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in Horde 3.1.6, Groupware prior to 1.0.5, and Groupware Webmail Edition prior to 1.0.6, when running with certain configurations, allows remote authenticated users to read and execute arbitrary files via ".." sequences and a null byte in the theme name.

Vulnerable Product Search on Vulmon Subscribe to Product

horde groupware webmail edition

horde horde 3.1.6

horde groupware

Vendor Advisories

It was discovered that the Horde web application framework permits arbitrary file inclusion by a remote attacker through the theme preference parameter For the old stable distribution (sarge) this problem has been fixed in version 304-4sarge7 For the stable distribution (etch) this problem has been fixed in version 313-4etch3 For the unstabl ...