CVE Vulnerabilities

CVE-2009-3236

Published: Sep 17, 2009 | Modified: Jun 18, 2019
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The form library in Horde Application Framework 3.2 before 3.2.5 and 3.3 before 3.3.5; Groupware 1.1 before 1.1.6 and 1.2 before 1.2.4; and Groupware Webmail Edition 1.1 before 1.1.6 and 1.2 before 1.2.4; reuses temporary filenames during the upload process which allows remote attackers, with privileges to write to the address book, to overwrite arbitrary files and execute PHP code via crafted Horde_Form_Type_image form field elements.

Affected Software

Name Vendor Start Version End Version
Application_framework Horde 3.2 3.2
Application_framework Horde 3.2.1 3.2.1
Application_framework Horde 3.2.2 3.2.2
Application_framework Horde 3.2.3 3.2.3
Application_framework Horde 3.2.4 3.2.4
Application_framework Horde 3.3 3.3
Application_framework Horde 3.3.1 3.3.1
Application_framework Horde 3.3.2 3.3.2
Application_framework Horde 3.3.3 3.3.3
Application_framework Horde 3.3.4 3.3.4
Groupware Horde 1.1 1.1
Groupware Horde 1.1.1 1.1.1
Groupware Horde 1.1.2 1.1.2
Groupware Horde 1.1.3 1.1.3
Groupware Horde 1.1.4 1.1.4
Groupware Horde 1.1.5 1.1.5
Groupware Horde 1.2 1.2
Groupware Horde 1.2 1.2
Groupware Horde 1.2.1 1.2.1
Groupware Horde 1.2.2 1.2.2
Groupware Horde 1.2.3 1.2.3

References