CVE-2012-0209
Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2012, contains an externally introduced modification (Trojan Horse) in templates/javascript/open_calendar.js,…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 71.9%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2012, contains an externally introduced modification (Trojan Horse) in templates/javascript/open_calendar.js, which allows remote attackers to execute arbitrary PHP code.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 71.90% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- horde/groupware · horde/horde
- Source
- security@debian.org
References
- http://dev.horde.org/h/jonah/stories/view.php?channel_id=1&id=155Exploit, Patch, Vendor Advisory
- http://eromang.zataz.com/2012/02/15/cve-2012-0209-horde-backdoor-analysis/Exploit
- http://lists.horde.org/archives/announce/2012/000751.htmlExploit, Patch
- http://packetstormsecurity.org/files/109874/Horde-3.3.12-Backdoor-Arbitrary-PHP-Code-Execution.htmlExploit
- https://bugzilla.redhat.com/show_bug.cgi?id=790877Patch
- http://dev.horde.org/h/jonah/stories/view.php?channel_id=1&id=155Exploit, Patch, Vendor Advisory
- http://eromang.zataz.com/2012/02/15/cve-2012-0209-horde-backdoor-analysis/Exploit
- http://lists.horde.org/archives/announce/2012/000751.htmlExploit, Patch
- http://packetstormsecurity.org/files/109874/Horde-3.3.12-Backdoor-Arbitrary-PHP-Code-Execution.htmlExploit
- https://bugzilla.redhat.com/show_bug.cgi?id=790877Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.