Horde Form Shell Upload
Posted by deepcore on April 11, 2019 – 1:20 am
Horde Groupware Webmail contains a flaw that allows an authenticated remote attacker to execute arbitrary PHP code. The exploitation requires the Turba subcomponent to be installed. This module was tested on Horde versions 5.2.22 and 5.2.17 running Horde Form subcomponent versions prior to 2.0.19.
Post a reply
You must be logged in to post a comment.