CVE-2006-1491: Code Injection
Published Mar 29, 2006
·Updated
Eval injection vulnerability in Horde Application Framework versions 3.0 before 3.0.10 and 3.1 before 3.1.1 allows remote attackers to execute arbitrary code via the help viewer.
Affected Software
12 affected components
Horde Application Framework=3.0.2
Horde Application Framework=3.0.8
Horde Application Framework=3.0
Horde Application Framework=3.0.4_rc1
Horde Application Framework=3.0.7
Horde Application Framework=3.0.4
Horde Application Framework=3.1
Horde Application Framework=3.0.1
Horde Application Framework=3.0.6
Horde Application Framework=3.0.3
Horde Application Framework=3.0.4_rc2
Horde Application Framework=3.0.9
Remediation
Patch Available
Patch Available
Patch Available
Event History
Mar 29, 2006
CVE Published
10:02 PM
Mar 30, 2006
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1491?
CVE-2006-1491 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2006-1491?
To mitigate CVE-2006-1491, upgrade the Horde Application Framework to version 3.0.10 or 3.1.1 or newer.
3
Which versions are affected by CVE-2006-1491?
CVE-2006-1491 affects Horde Application Framework versions prior to 3.0.10 and 3.1 before 3.1.1.
4
What types of attacks are possible with CVE-2006-1491?
CVE-2006-1491 allows remote attackers to execute arbitrary code via the help viewer in the affected versions.
5
Is CVE-2006-1491 still a concern in modern applications?
Yes, CVE-2006-1491 remains a concern for systems using outdated versions of the Horde Application Framework.