Where
-Infinity
0
Severity
4.3
XSS
AV:N/AC:M/Au:N/C:N/I:P/A:N

Multiple cross-site scripting (XSS) vulnerabilities in fetchmailprefs.php in Horde IMP before 4.3.8, and Horde Groupware Webmail Edition before 1.2.7, allow remote attackers to inject arbitrary web script or HTML via the (1) username (aka fmusername), (2) password (aka fmpassword), or (3) server (aka fmserver) field in a fetchmailprefssave action, related to the Fetchmail configuration, a different issue than CVE-2010-3695. NOTE: some of these details are obtained from third party information.

First published (updated )
Severity
7.5
Code Injection
AV:N/AC:L/Au:N/C:P/I:P/A:P

From http://dev.horde.org/h/jonah/stories/view.php?channelid=1&id=155

A few days ago we became aware of a manipulated file on our FTP server. Upon further investigation we discovered that the server has been hacked earlier, and three releases have been manipulated to allow unauthenticated remote PHP execution. We have immediately taken down all distribution servers to further analyze the extent of this incident, and we have worked closely with various Linux distributions to coordinate our response. Since then the FTP and PEAR servers have been replaced and further secured. Clean versions of our releases have been uploaded.

This issue will be tracked as CVE-2012-0209: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0209

We have been able to limit the manipulation to three files downloaded during a certain timeframe. The affected releases are: - Horde 3.3.12 downloaded between November 15 and February 7 - Horde Groupware 1.2.10 downloaded between November 9 and February 7 - Horde Groupware Webmail Edition 1.2.10 downloaded between November 2 and February 7

No other releases have been affected. Specifically, no Horde 4 releases were compromised. Our CVS and Git repositories are not affected either. Linux distributions that are affected will notify and provide security releases individually.

If you are not sure whether you are affected or want to verify manually whether you are affected, you can search for this signature in your Horde directory tree:

$m1

We recommend that all users of the affected version immediately re-install using fresh copies downloaded from our FTP server, or to upgrade to the more recent versions that have been released since then. This is a list of suggested replacements and their MD5 checksums:

bc04ce4499af24a403429c81d0a8afcf ftp://ftp.horde.org/pub/horde/horde-3.3.12.tar.gz 5a0486a5f6f96a9957e770ddabe71b38 ftp://ftp.horde.org/pub/horde/horde-3.3.13.tar.gz 4bdab16c84513bbd9466cb0dc7464661 ftp://ftp.horde.org/pub/horde-groupware/horde-groupware-1.2.10.tar.gz fed921b55a8f544fba806333502cd45d ftp://ftp.horde.org/pub/horde-groupware/horde-groupware-1.2.11.tar.gz 60e100c3e4ab59c01d30bf5eb813a182 ftp://ftp.horde.org/pub/horde-webmail/horde-webmail-1.2.10.tar.gz 6f735266449bfda2cce8b5067b16ff74 ftp://ftp.horde.org/pub/horde-webmail/horde-webmail-1.2.11.tar.gz

If you are running Horde 4, you don't need to do anything.

We apologize for the inconvenience and assure you that we are undertaking a full security review of our procedures to prevent this kind of incident from happening again.

If you have further questions, please ask on the Horde mailing list: http://www.horde.org/community/mail

1 / 2
Source: Red Hat
First published (updated )
Severity
10
AV:N/AC:L/Au:N/C:C/I:C/A:C

Unspecified vulnerability in the Horde API in Horde 3.1 before 3.1.6 and 3.2 before 3.2 before 3.2-RC2; Turba H3 2.1 before 2.1.6 and 2.2 before 2.2-RC2; Kronolith H3 2.1 before 2.1.7 and H3 2.2 before 2.2-RC2; Nag H3 2.1 before 2.1.4 and 2.2 before 2.2-RC2; Mnemo H3 2.1 before 2.1.2 and 2.2 before 2.2-RC2; Horde Groupware 1.0 before 1.0.3 and 1.1 before 1.1-RC2; and Groupware Webmail Edition 1.0 before 1.0.4 and 1.1 before 1.1-RC2 has unknown impact and attack vectors.

First published (updated )
Severity
4.3
XSS
AV:N/AC:M/Au:N/C:N/I:P/A:N

Cross-site scripting (XSS) vulnerability in MIME/MIME/Contents.php in the MIME library in Horde 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via the filename of a MIME attachment in an e-mail message.

First published (updated )
Severity
4.3
XSS
AV:N/AC:M/Au:N/C:N/I:P/A:N

Cross-site scripting (XSS) vulnerability in (1) TextFilter/Filter/xss.php in Horde 3.1.x before 3.1.9 and 3.2.x before 3.2.2 and (2) externalinput.php in Popoon r22196 and earlier allows remote attackers to inject arbitrary web script or HTML by using / (slash) characters as replacements for spaces in an HTML e-mail message.

First published (updated )
Severity
4.3
XSS
AV:N/AC:M/Au:N/C:N/I:P/A:N

Cross-site scripting (XSS) vulnerability in services/obrowser/index.php in Horde 3.2 and Turba 2.2 allows remote attackers to inject arbitrary web script or HTML via the contact name.

First published (updated )
Severity
6
Path Traversal
AV:N/AC:M/Au:S/C:P/I:P/A:P

Directory traversal vulnerability in Horde 3.1.6, Groupware before 1.0.5, and Groupware Webmail Edition before 1.0.6, when running with certain configurations, allows remote authenticated users to read and execute arbitrary files via ".." sequences and a null byte in the theme name.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:P/I:N/A:N

The IMP plugin in Horde allows remote attackers to bypass firewall restrictions and use Horde as a proxy to scan internal networks via a crafted request to an unspecified test script. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's installation documentation.

1 / 2
First published (updated )
Severity
4.3
XSS
AV:N/AC:M/Au:N/C:N/I:P/A:N

Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP before 5.0.18 and Horde Groupware Webmail Edition before 4.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) composeCache, (2) rtemode, or (3) filename parameters to the compose page; (4) formname parameter to the contacts popup window; or (5) IMAP mailbox names. NOTE: some of these details are obtained from third party information.

1 / 2
Source: MITRE
First published (updated )
Severity
5.7
Input Validation
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H

Denial of Service was found in HordeImage 2.x before 2.5.0 via a crafted URL to the "Null" image driver.

First published (updated )
Severity
4

From http://dev.horde.org/h/jonah/stories/view.php?channelid=1&id=155

A few days ago we became aware of a manipulated file on our FTP server. Upon further investigation we discovered that the server has been hacked earlier, and three releases have been manipulated to allow unauthenticated remote PHP execution. We have immediately taken down all distribution servers to further analyze the extent of this incident, and we have worked closely with various Linux distributions to coordinate our response. Since then the FTP and PEAR servers have been replaced and further secured. Clean versions of our releases have been uploaded.

This issue will be tracked as CVE-2012-0209: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0209

We have been able to limit the manipulation to three files downloaded during a certain timeframe. The affected releases are: - Horde 3.3.12 downloaded between November 15 and February 7 - Horde Groupware 1.2.10 downloaded between November 9 and February 7 - Horde Groupware Webmail Edition 1.2.10 downloaded between November 2 and February 7

No other releases have been affected. Specifically, no Horde 4 releases were compromised. Our CVS and Git repositories are not affected either. Linux distributions that are affected will notify and provide security releases individually.

If you are not sure whether you are affected or want to verify manually whether you are affected, you can search for this signature in your Horde directory tree:

$m1

We recommend that all users of the affected version immediately re-install using fresh copies downloaded from our FTP server, or to upgrade to the more recent versions that have been released since then. This is a list of suggested replacements and their MD5 checksums:

bc04ce4499af24a403429c81d0a8afcf ftp://ftp.horde.org/pub/horde/horde-3.3.12.tar.gz 5a0486a5f6f96a9957e770ddabe71b38 ftp://ftp.horde.org/pub/horde/horde-3.3.13.tar.gz 4bdab16c84513bbd9466cb0dc7464661 ftp://ftp.horde.org/pub/horde-groupware/horde-groupware-1.2.10.tar.gz fed921b55a8f544fba806333502cd45d ftp://ftp.horde.org/pub/horde-groupware/horde-groupware-1.2.11.tar.gz 60e100c3e4ab59c01d30bf5eb813a182 ftp://ftp.horde.org/pub/horde-webmail/horde-webmail-1.2.10.tar.gz 6f735266449bfda2cce8b5067b16ff74 ftp://ftp.horde.org/pub/horde-webmail/horde-webmail-1.2.11.tar.gz

If you are running Horde 4, you don't need to do anything.

We apologize for the inconvenience and assure you that we are undertaking a full security review of our procedures to prevent this kind of incident from happening again.

If you have further questions, please ask on the Horde mailing list: http://www.horde.org/community/mail

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203