Vulnerability Name: | CVE-2015-7984 (CCN-108151) | ||||||||||||||||||||||||||||||||||||||||||||
Assigned: | 2015-11-18 | ||||||||||||||||||||||||||||||||||||||||||||
Published: | 2015-11-18 | ||||||||||||||||||||||||||||||||||||||||||||
Updated: | 2021-05-19 | ||||||||||||||||||||||||||||||||||||||||||||
Summary: | Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware Webmail Edition before 5.2.11 allow remote attackers to hijack the authentication of administrators for requests that execute arbitrary (1) commands via the cmd parameter to admin/cmdshell.php, (2) SQL queries via the sql parameter to admin/sqlshell.php, or (3) PHP code via the php parameter to admin/phpshell.php. | ||||||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 8.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) 7.7 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-352 | ||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-7984 Source: MLIST Type: Vendor Advisory [announce] 20151021 [SECURITY] Horde 5.2.8 (final) Source: MLIST Type: Vendor Advisory [announce] 20151022 [SECURITY] Horde Groupware 5.2.11 (final) Source: MLIST Type: Vendor Advisory [announce] 20151022 [SECURITY] Horde Groupware Webmail Edition 5.2.11 (final) Source: DEBIAN Type: Third Party Advisory DSA-3391 Source: CCN Type: Horde Web site The Horde Project Source: XF Type: UNKNOWN horde-cve20157984-csrf(108151) Source: CCN Type: Packet Storm Security [11-19-2015] Horde Groupware 5.2.10 Cross Site Request Forgery Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [11-19-2015] Source: EXPLOIT-DB Type: Third Party Advisory, VDB Entry 38765 Source: CCN Type: HTB23272 RCE and SQL injection via CSRF in Horde Groupware Source: MISC Type: Exploit https://www.htbridge.com/advisory/HTB23272 Source: CCN Type: WhiteSource Vulnerability Database CVE-2015-7984 | ||||||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||
BACK |