Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2008-1284
Description:Directory traversal vulnerability in Horde 3.1.6, Groupware before 1.0.5, and Groupware Webmail Edition before 1.0.6, when running with certain configurations, allows remote authenticated users to read and execute arbitrary files via ".." sequences and a null byte in the theme name.
Test IDs: 1.3.6.1.4.1.25623.1.0.860062   1.3.6.1.4.1.25623.1.0.60571   1.3.6.1.4.1.25623.1.0.860917   1.3.6.1.4.1.25623.1.0.60939  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2008-1284
BugTraq ID: 28153
http://www.securityfocus.com/bid/28153
Bugtraq: 20080307 Horde Webmail file inclusion proof of concept & patch. (Google Search)
http://www.securityfocus.com/archive/1/489239/100/0/threaded
Bugtraq: 20080308 Re: Horde Webmail file inclusion proof of concept & patch. (Google Search)
http://www.securityfocus.com/archive/1/489289/100/0/threaded
Debian Security Information: DSA-1519 (Google Search)
http://www.debian.org/security/2008/dsa-1519
https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00253.html
https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00301.html
http://security.gentoo.org/glsa/glsa-200805-01.xml
http://lists.horde.org/archives/announce/2008/000383.html
http://lists.horde.org/archives/announce/2008/000384.html
http://lists.horde.org/archives/announce/2008/000382.html
http://secunia.com/advisories/29286
http://secunia.com/advisories/29374
http://secunia.com/advisories/29400
http://secunia.com/advisories/30047
http://securityreason.com/securityalert/3726
http://www.vupen.com/english/advisories/2008/0822/references
XForce ISS Database: horde-theme-file-include(41054)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41054




© 1998-2025 E-Soft Inc. All rights reserved.