CVE-2012-0209

H

orde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2012, contains an externally introduced modification (Trojan Horse) in templates/javascript/open_calendar.js, which allows remote attackers to execute arbitrary PHP code.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:horde:groupware:1.2.10:*:*:*:*:*:*:*
cpe:2.3:a:horde:groupware:1.2.10:*:webmail:*:*:*:*:*
cpe:2.3:a:horde:horde:3.3.12:*:*:*:*:*:*:*

History

21 Nov 2024, 01:34

Type Values Removed Values Added
References () http://dev.horde.org/h/jonah/stories/view.php?channel_id=1&id=155 - Exploit, Patch, Vendor Advisory () http://dev.horde.org/h/jonah/stories/view.php?channel_id=1&id=155 - Exploit, Patch, Vendor Advisory
References () http://eromang.zataz.com/2012/02/15/cve-2012-0209-horde-backdoor-analysis/ - Exploit () http://eromang.zataz.com/2012/02/15/cve-2012-0209-horde-backdoor-analysis/ - Exploit
References () http://lists.horde.org/archives/announce/2012/000751.html - Exploit, Patch () http://lists.horde.org/archives/announce/2012/000751.html - Exploit, Patch
References () http://packetstormsecurity.org/files/109874/Horde-3.3.12-Backdoor-Arbitrary-PHP-Code-Execution.html - Exploit () http://packetstormsecurity.org/files/109874/Horde-3.3.12-Backdoor-Arbitrary-PHP-Code-Execution.html - Exploit
References () https://bugzilla.redhat.com/show_bug.cgi?id=790877 - Patch () https://bugzilla.redhat.com/show_bug.cgi?id=790877 - Patch

Information

Published : 2012-09-25 22:55

Updated : 2025-04-11 00:51


NVD link : CVE-2012-0209

Mitre link : CVE-2012-0209

CVE.ORG link : CVE-2012-0209


JSON object : View

Products Affected
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')