CVE-2008-1284
Directory traversal vulnerability in Horde 3.1.6, Groupware before 1.0.5, and Groupware Webmail Edition before 1.0.6, when running with certain configurations, allows remote authenticated users to read and execute arbitrary files via ".." sequences and…
Does this matter?
Lower severity and a low EPSS score (1.68%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in Horde 3.1.6, Groupware before 1.0.5, and Groupware Webmail Edition before 1.0.6, when running with certain configurations, allows remote authenticated users to read and execute arbitrary files via ".." sequences and a null byte in the theme name.
- CVSS 2.0
- 6.0 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
- EPSS
- 1.68% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- horde/groupware · horde/groupware webmail edition · horde/horde
- Source
- cve@mitre.org
References
- http://lists.horde.org/archives/announce/2008/000382.htmlPatch
- http://lists.horde.org/archives/announce/2008/000383.html
- http://lists.horde.org/archives/announce/2008/000384.html
- http://secunia.com/advisories/29286Vendor Advisory
- http://secunia.com/advisories/29374Vendor Advisory
- http://secunia.com/advisories/29400Vendor Advisory
- http://secunia.com/advisories/30047Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200805-01.xml
- http://securityreason.com/securityalert/3726
- http://www.debian.org/security/2008/dsa-1519
- http://www.securityfocus.com/archive/1/489239/100/0/threaded
- http://www.securityfocus.com/archive/1/489289/100/0/threaded
- http://www.securityfocus.com/bid/28153Patch
- http://www.vupen.com/english/advisories/2008/0822/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41054
- https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00253.html
- https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00301.html
- http://lists.horde.org/archives/announce/2008/000382.htmlPatch
- http://lists.horde.org/archives/announce/2008/000383.html
- http://lists.horde.org/archives/announce/2008/000384.html
- http://secunia.com/advisories/29286Vendor Advisory
- http://secunia.com/advisories/29374Vendor Advisory
- http://secunia.com/advisories/29400Vendor Advisory
- http://secunia.com/advisories/30047Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200805-01.xml
- http://securityreason.com/securityalert/3726
- http://www.debian.org/security/2008/dsa-1519
- http://www.securityfocus.com/archive/1/489239/100/0/threaded
- http://www.securityfocus.com/archive/1/489289/100/0/threaded
- http://www.securityfocus.com/bid/28153Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.