Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-1691

Опубликовано: 01 апр. 2014
Источник: debian

Описание

The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injection attacks and execute arbitrary PHP code via a crafted serialized object in the _formvars form.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
horde3removedpackage
php-horde-utilfixed2.3.0-1package

Примечания

  • https://github.com/horde/horde/commit/da6afc7e9f4e290f782eca9dbca794f772caccb3

  • https://github.com/horde/horde/commit/acf67ab4a633037849aca9e4a7592465b999ad93 is also required

Связанные уязвимости

ubuntu
почти 12 лет назад

The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injection attacks and execute arbitrary PHP code via a crafted serialized object in the _formvars form.

nvd
почти 12 лет назад

The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injection attacks and execute arbitrary PHP code via a crafted serialized object in the _formvars form.

github
больше 3 лет назад

The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injection attacks and execute arbitrary PHP code via a crafted serialized object in the _formvars form.