CVE-2014-1691

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
01/04/2014
Last modified:
02/04/2014

Description

The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injection attacks and execute arbitrary PHP code via a crafted serialized object in the _formvars form.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:horde:horde_application_framework:*:*:*:*:*:*:*:* 5.1.0 (including)
cpe:2.3:a:horde:horde_application_framework:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:horde:horde_application_framework:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:horde:horde_application_framework:5.0.2:*:*:*:*:*:*:*
cpe:2.3:a:horde:horde_application_framework:5.0.3:*:*:*:*:*:*:*
cpe:2.3:a:horde:horde_application_framework:5.0.4:*:*:*:*:*:*:*