|
|
Info |
Last Modified |
| 2 months ago |
|
|
|
|
|
Description |
Horde contains a flaw that may lead to an unauthorized information disclosure. The issue is due to go.php not properly sanitizing user input supplied to the 'url' variable. Embedding a NULL character within the 'url' variable enables an attacker to control the variable passed to readfile() function leading to the reading of any file on the file system with the privileges of the web server resulting in a loss of confidentiality.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Confidentiality
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
OSVDB:
Web Related
|
|
Solution |
Upgrade to version 3.1 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
Horde
 |
3.0.9 |
|
|
|
|
|
|
|
Credit |
- Paul Craig - paul.craigsecurity-assessment.com - security-assessment.com
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|