This CPE summary could be partial or incomplete. Please contact us for a detailed listing.
Summary
| Summuary | |
|---|---|
| CPE Name | cpe:/a:horde:groupware |
| Detail | |||
|---|---|---|---|
| Vendor | Horde | First view | 2007-01-30 |
| Product | Groupware | Last view | 2012-09-25 |
| Version | Type | Application | |
| Edition | |||
| Language | |||
| Update | |||
Activity : Yearly
COMMON PLATFORM ENUMERATION : Repartition per Version
Related : CVE
| Date | Alert | Access Vector | Access Complexity | Authentification | ||
|---|---|---|---|---|---|---|
| 7.5 | 2012-09-25 | CVE-2012-0209 | Network | Low | None Requ... | |
| 4.3 | 2011-04-04 | CVE-2010-4778 | Network | Medium | None Requ... | |
| 4.3 | 2011-04-04 | CVE-2010-3693 | Network | Medium | None Requ... | |
| 4.3 | 2011-03-31 | CVE-2010-3695 | Network | Medium | None Requ... | |
| 4.3 | 2009-12-21 | CVE-2009-4363 | Network | Medium | None Requ... | |
| Date | Alert | Access Vector | Access Complexity | Authentification | ||
|---|---|---|---|---|---|---|
| 4.3 | 2009-12-21 | CVE-2009-3701 | Network | Medium | None Requ... | |
| 4.3 | 2009-09-17 | CVE-2009-3237 | Network | Medium | None Requ... | |
| 4.3 | 2009-09-17 | CVE-2009-3236 | Network | Medium | None Requ... | |
| 10 | 2009-09-13 | CVE-2008-7219 | Network | Low | None Requ... | |
| 10 | 2009-09-13 | CVE-2008-7218 | Network | Low | None Requ... | |
| 4.3 | 2008-06-19 | CVE-2008-2783 | Network | Medium | None Requ... | |
| 4.3 | 2008-04-27 | CVE-2008-1974 | Network | Medium | None Requ... | |
| 6 | 2008-03-10 | CVE-2008-1284 | Network | Medium | Requires ... | |
| 4.9 | 2008-02-18 | CVE-2008-0807 | Network | Medium | Requires ... | |
| 4.3 | 2007-03-26 | CVE-2007-1679 | Network | Medium | None Requ... | |
| 5.1 | 2007-01-30 | CVE-2007-0579 | Network | High | None Requ... |
CWE : Common Weakness Enumeration
| % | id | Name |
|---|---|---|
| 66% (8) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
| 16% (2) | CWE-264 | Permissions, Privileges, and Access Controls |
| 8% (1) | CWE-94 | Failure to Control Generation of Code ('Code Injection') |
| 8% (1) | CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path ... |
CAPEC : Common Attack Pattern Enumeration & Classificatio
This CPE Product have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
| id | Name |
|---|---|
| CAPEC-3 | Using Leading 'Ghost' Character Sequences to Bypass Input Filters |
| CAPEC-7 | Blind SQL Injection |
| CAPEC-8 | Buffer Overflow in an API Call |
| CAPEC-9 | Buffer Overflow in Local Command-Line Utilities |
| CAPEC-10 | Buffer Overflow via Environment Variables |
| id | Name |
|---|---|
| CAPEC-13 | Subverting Environment Variable Values |
| CAPEC-14 | Client-side Injection-induced Buffer Overflow |
| CAPEC-18 | Embedding Scripts in Nonscript Elements |
| CAPEC-22 | Exploiting Trust in Client (aka Make the Client Invisible) |
| CAPEC-24 | Filter Failure through Buffer Overflow |
| CAPEC-28 | Fuzzing |
| CAPEC-31 | Accessing/Intercepting/Modifying HTTP Cookies |
| CAPEC-32 | Embedding Scripts in HTTP Query Strings |
| CAPEC-42 | MIME Conversion |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
| CAPEC-45 | Buffer Overflow via Symbolic Links |
| CAPEC-46 | Overflow Variables and Tags |
| CAPEC-47 | Buffer Overflow via Parameter Expansion |
| CAPEC-52 | Embedding NULL Bytes |
| CAPEC-53 | Postfix, Null Terminate, and Backslash |
| CAPEC-63 | Simple Script Injection |
| CAPEC-64 | Using Slashes and URL Encoding Combined to Bypass Validation Logic |
| CAPEC-66 | SQL Injection |
| CAPEC-67 | String Format Overflow in syslog() |
| CAPEC-71 | Using Unicode Encoding to Bypass Validation Logic |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 68267 | Horde DIMP Mailbox Page Folder Label XSS |
| 68261 | Horde IMP fetchmailprefs.php fm_id Parameter XSS |
| 61338 | Horde Xss.php Filter Bypass data:// URI XSS |
| 61304 | Horde Administration Interface admin/sqlshell.php PATH_INFO Parameter XSS |
| 61303 | Horde Administration Interface admin/cmdshell.php PATH_INFO Parameter XSS |
| id | Description |
|---|---|
| 61043 | Horde Administration Interface admin/phpshell.php PATH_INFO Parameter XSS |
| 58109 | Horde Application Framework Numeric Preference Type XSS |
| 58108 | Horde Application Framework MIME Viewer Text Part Rendering XSS |
| 58107 | Horde Application Framework Form Library Image Form Field Arbitrary File Over... |
| 46702 | Horde Multiple Product day.php PATH_INFO XSS |
| 46701 | Horde Multiple Product workweek.php PATH_INFO XSS |
| 46700 | Horde Multiple Product week.php PATH_INFO XSS |
| 44557 | Kronolith addevent.php url Parameter XSS |
| 42779 | Horde Turba 2 (turba2) Contact Manager H3 lib/Driver/sql.php Unauthorized Dat... |
| 42776 | Horde Multiple Products Share Management Owner Validation Unspecified Issue |
| 42775 | Horde Multiple Products API Unspecified Privilege Escalation |
| 42774 | Horde Multiple Products theme Parameter Traversal Local File Inclusion |
| 35181 | Horde Webmail ingo/rule.php XSS |
| 33083 | Horde Groupware Calendar Component Unspecified Issue |
ExploitDB Exploits
| id | Description |
|---|---|
| 18492 | Horde 3.3.12 Backdoor Arbitrary PHP Code Execution |
| 10512 | Horde 3.3.5 "PHP_SELF" XSS vulnerability |
Metasploit Exploits
| id | Description |
|---|---|
| 2012-02-13 | Horde 3.3.12 Backdoor Arbitrary PHP Code Execution |











