First published: Tue Mar 17 2009(Updated: )
Directory traversal vulnerability in framework/Image/Image.php in Horde before 3.2.4 and 3.3.3 and Horde Groupware before 1.1.5 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Horde_Image driver name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Horde | =3.2 | |
Horde | =3.2.2 | |
Horde | =3.2.3 | |
Horde | =3.3 | |
Horde | =3.3.1 | |
Horde | =3.3.2 | |
Horde Groupware | =1.1.1 | |
Horde Groupware | =1.1.2 | |
Horde Groupware | =1.1.3 | |
Horde Groupware | =1.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0932 is considered a critical vulnerability as it allows remote attackers to execute arbitrary local files.
To resolve CVE-2009-0932, you should upgrade to Horde versions 3.2.4, 3.3.3 or later, or Horde Groupware version 1.1.5 or later.
CVE-2009-0932 allows directory traversal attacks that can lead to remote code execution on affected systems.
CVE-2009-0932 affects Horde versions prior to 3.2.4 and 3.3.3, as well as Horde Groupware versions prior to 1.1.5.
The impact of CVE-2009-0932 may include unauthorized access to sensitive data and the possibility of system compromise.