CVE-2007-1474: Medium severity Horde Horde Application Framework vulnerability
Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows local users to delete arbitrary files and possibly gain privileges via multiple space-delimited pathnames.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1474?
CVE-2007-1474 is considered a moderate severity vulnerability as it allows local users to delete arbitrary files.
How do I fix CVE-2007-1474?
To fix CVE-2007-1474, upgrade to Horde Application Framework version 3.1.4 or later.
Which versions of Horde are affected by CVE-2007-1474?
CVE-2007-1474 affects Horde IMP versions 2.0 to 2.2.8 and 3.0 to 3.2.6, along with Horde Application Framework versions 3.0.0 to 3.1.3.
What is the impact of CVE-2007-1474?
The impact of CVE-2007-1474 allows local users to potentially gain elevated privileges by deleting arbitrary files.
Who can exploit CVE-2007-1474?
CVE-2007-1474 can be exploited by local users who have access to the cleanup cron script.