Vulnerability Description
Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows local users to delete arbitrary files and possibly gain privileges via multiple space-delimited pathnames.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Horde | Horde Application Framework | 3.0.0 |
| Horde | Imp | 2.0 |
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=489Vendor Advisory
- http://lists.horde.org/archives/announce/2007/000315.htmlPatchVendor Advisory
- http://secunia.com/advisories/27565
- http://www.debian.org/security/2007/dsa-1406
- http://www.securityfocus.com/bid/22985
- http://www.securitytracker.com/id?1017784
- http://www.securitytracker.com/id?1017785
- http://www.vupen.com/english/advisories/2007/0965
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32997
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=489Vendor Advisory
- http://lists.horde.org/archives/announce/2007/000315.htmlPatchVendor Advisory
- http://secunia.com/advisories/27565
- http://www.debian.org/security/2007/dsa-1406
- http://www.securityfocus.com/bid/22985
- http://www.securitytracker.com/id?1017784
FAQ
What is CVE-2007-1474?
CVE-2007-1474 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows local users to delete arbitrary files and possibly gain privi...
How severe is CVE-2007-1474?
CVE-2007-1474 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-1474?
Check the references section above for vendor advisories and patch information. Affected products include: Horde Horde Application Framework, Horde Imp.