Horde < 3.3.3 / 3.2.4 Horde_Image::factory driver Argument Local File Inclusion

High Nessus Network Monitor Plugin ID 4835

Synopsis

The remote web server contains a PHP application that is susceptible to a local file inclusion attack.

Description

The version of Horde, Horde Groupware, or Horde Groupware Webmail Edition installed on the remote host fails to filter input to the 'driver' argument of the 'Horde_Image: : factory' method before using it to include PHP code in 'lib/Horde/Image.php'. Regardless of PHP's 'register_globals' and 'magic_quotes_gpc' settings, an unauthenticated attacker can exploit this issue to view arbitrary files or possibly to execute arbitrary PHP code on the remote host, subject to the privileges of the web server user ID.

Note that this install is also likely affected by a cross-site scripting issue in the 'services/portal/cloud_search.php' script.

Solution

Upgrade to version 3.3.3 / 3.2.4 or higher.

See Also

http://lists.horde.org/archives/announce/2009/000482.html

http://lists.horde.org/archives/announce/2009/000483.html

http://lists.horde.org/archives/announce/2009/000486.html

http://lists.horde.org/archives/announce/2009/000487.html

http://lists.horde.org/archives/announce/2009/000488.html

http://lists.horde.org/archives/announce/2009/000489.html

http://www.securityfocus.com/bid/33491

Plugin Details

Severity: High

ID: 4835

Family: CGI

Published: 2009/01/29

Modified: 2018/07/11

Dependencies: 1442

Nessus ID: 35554

Risk Information

Risk Factor: High

CVSSv2

Base Score: 7.5

Temporal Score: 6.2

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:F/RL:OF/RC:C

CVSSv3

Base Score: 7.3

Temporal Score: 6.8

Vector: CVSS3#AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS3#E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:debian:horde

Exploitable With

CANVAS (D2ExploitPack)

Reference Information

CVE: CVE-2009-0931, CVE-2009-0932

BID: 33491