Back to search
CVE-2012-0209
Published: Sep 25, 2012
Modified: Sep 16, 2024
PUBLISHED
Description
Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2012, contains an externally introduced modification (Trojan Horse) in templates/javascript/open_calendar.js, which allows remote attackers to execute arbitrary PHP code.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://dev.horde.org/h/jonah/stories/view.php?channel_id=1&id=155
x_refsource_CONFIRM
https://bugzilla.redhat.com/show_bug.cgi?id=790877
x_refsource_MISC
[horde-announce] 20120213 [SECURITY] Remote execution backdoor after server hack (CVE-2012-0209)
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now