Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vrpw-h28p-3rfp

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injection attacks and execute arbitrary PHP code via a crafted serialized object in the _formvars form.

The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injection attacks and execute arbitrary PHP code via a crafted serialized object in the _formvars form.

EPSS

Процентиль: 99%
0.8135
Высокий

Дефекты

CWE-94

Связанные уязвимости

ubuntu
почти 12 лет назад

The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injection attacks and execute arbitrary PHP code via a crafted serialized object in the _formvars form.

nvd
почти 12 лет назад

The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injection attacks and execute arbitrary PHP code via a crafted serialized object in the _formvars form.

debian
почти 12 лет назад

The framework/Util/lib/Horde/Variables.php script in the Util library ...

EPSS

Процентиль: 99%
0.8135
Высокий

Дефекты

CWE-94