SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2008-1284

Directory traversal vulnerability in Horde 3.1.6, Groupware before 1.0.5, and Groupware Webmail Edition before 1.0.6, when running with certain configurations, allows remote authenticated users to read and execute arbitrary files via ".." sequences and…

MEDIUM 6.0EPSS 1.68%

Does this matter?

Lower severity and a low EPSS score (1.68%). Track it; it rarely justifies an emergency change on its own.

Description

Directory traversal vulnerability in Horde 3.1.6, Groupware before 1.0.5, and Groupware Webmail Edition before 1.0.6, when running with certain configurations, allows remote authenticated users to read and execute arbitrary files via ".." sequences and a null byte in the theme name.

CVSS 2.0
6.0 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
EPSS
1.68% probability · 76th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
horde/groupware · horde/groupware webmail edition · horde/horde
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.