Back to search
CVE-2007-1474
Published: Mar 16, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows local users to delete arbitrary files and possibly gain privileges via multiple space-delimited pathnames.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20070315 Horde Project Cleanup Script Arbitrary File Deletion Vulnerability
third-party-advisory
x_refsource_IDEFENSE
1017784
vdb-entry
x_refsource_SECTRACK
27565
third-party-advisory
x_refsource_SECUNIA
horde-cron-file-deletion(32997)
vdb-entry
x_refsource_XF
22985
vdb-entry
x_refsource_BID
1017785
vdb-entry
x_refsource_SECTRACK
DSA-1406
vendor-advisory
x_refsource_DEBIAN
ADV-2007-0965
vdb-entry
x_refsource_VUPEN
[announce] 20070314 Horde 3.1.4 (final)
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now