Horde Framework Theme File Include Vulnerability
BID:28153
Info
Horde Framework Theme File Include Vulnerability
| Bugtraq ID: | 28153 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1284 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 08 2008 12:00AM |
| Updated: | Apr 16 2015 05:49PM |
| Credit: | Discovery is credited to David Collins and Patrick Pelanne of the HostGator.com LLC support team. |
| Vulnerable: |
Red Hat Fedora 7 Horde Project Horde 3.1.6 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: | |
Discussion
Horde Framework Theme File Include Vulnerability
Horde Framework is an application framework used with other Horde Project products. It is implemented in PHP.
Horde is prone to a file-include vulnerability because it fails to sufficiently sanitize user-supplied input. This vulnerability could let attackers include local files. Under certain configurations, the issue may also allow remote file-inclusion attacks.
Exploiting this issue may allow an attacker to gain access to files or execute arbitrary PHP code in the context of the application.
This issue was identified in Horde 3.1.6; other versions may also be affected.
NOTE: The vendor has confirmed that the vulnerability exists, but there are conflicting details about the nature of the exploit. Please see the references for the vendor's description.
Horde Framework is an application framework used with other Horde Project products. It is implemented in PHP.
Horde is prone to a file-include vulnerability because it fails to sufficiently sanitize user-supplied input. This vulnerability could let attackers include local files. Under certain configurations, the issue may also allow remote file-inclusion attacks.
Exploiting this issue may allow an attacker to gain access to files or execute arbitrary PHP code in the context of the application.
This issue was identified in Horde 3.1.6; other versions may also be affected.
NOTE: The vendor has confirmed that the vulnerability exists, but there are conflicting details about the nature of the exploit. Please see the references for the vendor's description.
Exploit / POC
Horde Framework Theme File Include Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Horde Framework Theme File Include Vulnerability
Solution:
The vendor has released a patch. Please see references for more information.
Solution:
The vendor has released a patch. Please see references for more information.
References
Horde Framework Theme File Include Vulnerability
References:
References: