4.3
CVE-2009-3236
- EPSS 0.84%
- Veröffentlicht 17.09.2009 10:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
The form library in Horde Application Framework 3.2 before 3.2.5 and 3.3 before 3.3.5; Groupware 1.1 before 1.1.6 and 1.2 before 1.2.4; and Groupware Webmail Edition 1.1 before 1.1.6 and 1.2 before 1.2.4; reuses temporary filenames during the upload process which allows remote attackers, with privileges to write to the address book, to overwrite arbitrary files and execute PHP code via crafted Horde_Form_Type_image form field elements.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Horde ≫ Application Framework Version3.2
Horde ≫ Application Framework Version3.2.1
Horde ≫ Application Framework Version3.2.2
Horde ≫ Application Framework Version3.2.3
Horde ≫ Application Framework Version3.2.4
Horde ≫ Application Framework Version3.3
Horde ≫ Application Framework Version3.3.1
Horde ≫ Application Framework Version3.3.2
Horde ≫ Application Framework Version3.3.3
Horde ≫ Application Framework Version3.3.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.84% | 0.725 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|