Horde Help Viewer Remote PHP Code Execution Vulnerability
BID:17292
Info
Horde Help Viewer Remote PHP Code Execution Vulnerability
| Bugtraq ID: | 17292 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-1491 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 28 2006 12:00AM |
| Updated: | Jul 19 2006 08:07PM |
| Credit: | The vendor disclosed this vulnerability. |
| Vulnerable: |
S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 Horde Project Horde 3.0.9 Horde Project Horde 3.0.8 Horde Project Horde 3.0.7 Horde Project Horde 3.0.6 Horde Project Horde 3.0.4 -RC 2 Horde Project Horde 3.0.4 -RC 1 Horde Project Horde 3.0.4 Horde Project Horde 3.0.3 Horde Project Horde 3.0.2 Horde Project Horde 3.0.1 Horde Project Horde 3.0 Horde Project Horde 3.1 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: |
Horde Project Horde 3.1.1 Horde Project Horde 3.0.10 |
Discussion
Horde Help Viewer Remote PHP Code Execution Vulnerability
Horde is prone to a remote PHP code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary malicious PHP code and in the context of the webserver process. This may help the attacker compromise the application and the underlying system; other attacks are also possible.
Horde versions 3.0 up to 3.0.9 and 3.1.0 are vulnerable; other versions may also be affected.
Horde is prone to a remote PHP code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary malicious PHP code and in the context of the webserver process. This may help the attacker compromise the application and the underlying system; other attacks are also possible.
Horde versions 3.0 up to 3.0.9 and 3.1.0 are vulnerable; other versions may also be affected.
Exploit / POC
Horde Help Viewer Remote PHP Code Execution Vulnerability
Attackers can exploit this issue via a web client.
The following proof-of-concept exploits are available:
Attackers can exploit this issue via a web client.
The following proof-of-concept exploits are available:
Solution / Fix
Horde Help Viewer Remote PHP Code Execution Vulnerability
Solution:
The vendor has released versions 3.0.10 and 3.1.1 to address this issue.
See the referenced vendor advisories for more information.
Horde Project Horde 3.1
Horde Project Horde 3.0
Horde Project Horde 3.0.1
Horde Project Horde 3.0.2
Horde Project Horde 3.0.3
Horde Project Horde 3.0.4
Horde Project Horde 3.0.4 -RC 1
Horde Project Horde 3.0.4 -RC 2
Horde Project Horde 3.0.6
Horde Project Horde 3.0.7
Horde Project Horde 3.0.8
Horde Project Horde 3.0.9
Solution:
The vendor has released versions 3.0.10 and 3.1.1 to address this issue.
See the referenced vendor advisories for more information.
Horde Project Horde 3.1
-
Horde horde-3.1.1.tar.gz
http://ftp.horde.org/pub/horde/horde-3.1.1.tar.gz
Horde Project Horde 3.0
-
Horde horde-3.0.10.tar.gz
http://ftp.horde.org/pub/horde/horde-3.0.10.tar.gz
Horde Project Horde 3.0.1
-
Horde horde-3.0.10.tar.gz
http://ftp.horde.org/pub/horde/horde-3.0.10.tar.gz
Horde Project Horde 3.0.2
-
Horde horde-3.0.10.tar.gz
http://ftp.horde.org/pub/horde/horde-3.0.10.tar.gz
Horde Project Horde 3.0.3
-
Horde horde-3.0.10.tar.gz
http://ftp.horde.org/pub/horde/horde-3.0.10.tar.gz
Horde Project Horde 3.0.4
-
Debian horde3_3.0.4-4sarge3_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/horde3/horde3_3.0.4-4sa rge3_all.deb -
Horde horde-3.0.10.tar.gz
http://ftp.horde.org/pub/horde/horde-3.0.10.tar.gz
Horde Project Horde 3.0.4 -RC 1
-
Horde horde-3.0.10.tar.gz
http://ftp.horde.org/pub/horde/horde-3.0.10.tar.gz
Horde Project Horde 3.0.4 -RC 2
-
Horde horde-3.0.10.tar.gz
http://ftp.horde.org/pub/horde/horde-3.0.10.tar.gz
Horde Project Horde 3.0.6
-
Horde horde-3.0.10.tar.gz
http://ftp.horde.org/pub/horde/horde-3.0.10.tar.gz
Horde Project Horde 3.0.7
-
Horde horde-3.0.10.tar.gz
http://ftp.horde.org/pub/horde/horde-3.0.10.tar.gz
Horde Project Horde 3.0.8
-
Horde horde-3.0.10.tar.gz
http://ftp.horde.org/pub/horde/horde-3.0.10.tar.gz
Horde Project Horde 3.0.9
-
Horde horde-3.0.10.tar.gz
http://ftp.horde.org/pub/horde/horde-3.0.10.tar.gz
References
Horde Help Viewer Remote PHP Code Execution Vulnerability
References:
References:
- [announce] Horde 3.1.1 (final) (Horde)
- Pandora Homepage (Pandora FMS Team)