CVE-2015-7984
Summary
| CVE | CVE-2015-7984 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-11-19 20:59:09 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware Webmail Edition before 5.2.11 allow remote attackers to hijack the authentication of administrators for requests that execute arbitrary (1) commands via the cmd parameter to admin/cmdshell.php, (2) SQL queries via the sql parameter to admin/sqlshell.php, or (3) PHP code via the php parameter to admin/phpshell.php. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Application | Horde | Groupware | All | All | All | All |
| Application | Horde | Groupware | All | All | All | All |
| Application | Horde | Horde Application Framework | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [announce] [SECURITY] Horde Groupware 5.2.11 (final) | af854a3a-2127-422b-91ae-364da2661108 | lists.horde.org | Vendor Advisory |
| File Not Found | af854a3a-2127-422b-91ae-364da2661108 | www.htbridge.com | Exploit |
| [announce] [SECURITY] Horde Groupware Webmail Edition 5.2.11 (final) | af854a3a-2127-422b-91ae-364da2661108 | lists.horde.org | Vendor Advisory |
| Debian -- Security Information -- DSA-3391-1 php-horde | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| [announce] [SECURITY] Horde 5.2.8 (final) | af854a3a-2127-422b-91ae-364da2661108 | lists.horde.org | Vendor Advisory |
| Horde Groupware 5.2.10 - Cross-Site Request Forgery - PHP webapps Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.