VulnerabilityModified
CVE-2006-1491
Eval injection vulnerability in Horde Application Framework versions 3.0 before 3.0.10 and 3.1 before 3.1.1 allows remote attackers to execute arbitrary code via the help viewer.
HIGH 7.5EPSS 38.4%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 38.4%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Eval injection vulnerability in Horde Application Framework versions 3.0 before 3.0.10 and 3.1 before 3.1.1 allows remote attackers to execute arbitrary code via the help viewer.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 38.44% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- horde/application framework
- Source
- cve@mitre.org
References
- http://cvs.horde.org/diff.php?f=horde%2Fservices%2Fhelp%2Findex.php&r1=2.85&r2=2.86
- http://lists.horde.org/archives/announce/2006/000271.htmlPatch
- http://lists.horde.org/archives/announce/2006/000272.html
- http://secunia.com/advisories/19485Vendor Advisory
- http://secunia.com/advisories/19504Vendor Advisory
- http://secunia.com/advisories/19528Vendor Advisory
- http://secunia.com/advisories/19619Vendor Advisory
- http://secunia.com/advisories/19692Vendor Advisory
- http://securitytracker.com/id?1015841Patch
- http://www.attrition.org/pipermail/vim/2006-March/000671.html
- http://www.debian.org/security/2006/dsa-1033
- http://www.debian.org/security/2006/dsa-1034
- http://www.gentoo.org/security/en/glsa/glsa-200604-02.xml
- http://www.novell.com/linux/security/advisories/2006_07_sr.html
- http://www.securityfocus.com/bid/17292Patch
- http://www.vupen.com/english/advisories/2006/1154Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25516
- http://cvs.horde.org/diff.php?f=horde%2Fservices%2Fhelp%2Findex.php&r1=2.85&r2=2.86
- http://lists.horde.org/archives/announce/2006/000271.htmlPatch
- http://lists.horde.org/archives/announce/2006/000272.html
- http://secunia.com/advisories/19485Vendor Advisory
- http://secunia.com/advisories/19504Vendor Advisory
- http://secunia.com/advisories/19528Vendor Advisory
- http://secunia.com/advisories/19619Vendor Advisory
- http://secunia.com/advisories/19692Vendor Advisory
- http://securitytracker.com/id?1015841Patch
- http://www.attrition.org/pipermail/vim/2006-March/000671.html
- http://www.debian.org/security/2006/dsa-1033
- http://www.debian.org/security/2006/dsa-1034
- http://www.gentoo.org/security/en/glsa/glsa-200604-02.xml
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.