RSS   Vulnerabilities for 'Horde groupware'   RSS

2017-04-04
 
CVE-2017-7414

CWE-78
 

 
In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition 5.x through 5.2.17, OS Command Injection can occur if the user has PGP features enabled in the user's preferences, and has enabled the "Should PGP signed messages be automatically verified when viewed?" preference. To exploit this vulnerability, an attacker can send a PGP signed email (that is maliciously crafted) to the Horde user, who then must either view or preview it.

 
 
CVE-2017-7413

CWE-78
 

 
In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition through 5.2.17, OS Command Injection can occur if the attacker is an authenticated Horde Webmail user, has PGP features enabled in their preferences, and attempts to encrypt an email addressed to a maliciously crafted email address.

 
2016-04-13
 
CVE-2016-2228

 

 
Cross-site scripting (XSS) vulnerability in horde/templates/topbar/_menubar.html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to inject arbitrary web script or HTML via the searchfield parameter, as demonstrated by a request to xplorer/gollem/manager.php.

 
 
CVE-2015-8807

 

 
Cross-site scripting (XSS) vulnerability in the _renderVarInput_number function in horde/framework/Core/lib/Horde/Core/Ui/VarRenderer/Html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to inject arbitrary web script or HTML via vectors involving numeric form fields.

 
2009-09-17
 
CVE-2009-3237

CWE-79
 

 
Multiple cross-site scripting (XSS) vulnerabilities in Horde Application Framework 3.2 before 3.2.5 and 3.3 before 3.3.5; Groupware 1.1 before 1.1.6 and 1.2 before 1.2.4; and Groupware Webmail Edition 1.1 before 1.1.6 and 1.2 before 1.2.4; allow remote attackers to inject arbitrary web script or HTML via the (1) crafted number preferences that are not properly handled in the preference system (services/prefs.php), as demonstrated by the sidebar_width parameter; or (2) crafted unknown MIME "text parts" that are not properly handled in the MIME viewer library (config/mime_drivers.php).

 

 >>> Vendor: Horde 32 Products
Horde
IMP
Application framework
Passwd
Kronolith
Turba
Accounts
Chora
Forwards
Mnemo
Vaction
NAG
Kronolith h3
Horde application framework
Nag task list manager h3
Turba h3
Ingo h3
Groupware
Framework
Groupware webmail edition
Turba contact manager
Turba contact manager h3
Mnemo h3
Nag h3
Horde groupware
Gollem
Dynamic imp
Kronolith h4
Internet mail program
Horde image api
Horde image
Horde imp


Copyright 2019, cxsecurity.com

 

Back to Top