Total vulnerabilities in the database
The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injection attacks and execute arbitrary PHP code via a crafted serialized object in the _formvars form.
Software | From | Fixed in |
---|---|---|
horde / horde_application_framework | 5.0.1 | 5.0.1.x |
horde / horde_application_framework | 5.0.4 | 5.0.4.x |
horde / horde_application_framework | - | 5.1.0.x |
horde / horde_application_framework | 5.0.2 | 5.0.2.x |
horde / horde_application_framework | 5.0.3 | 5.0.3.x |
horde / horde_application_framework | 5.0.0 | 5.0.0.x |