CVE-2009-3236
The form library in Horde Application Framework 3.2 before 3.2.5 and 3.3 before 3.3.5; Groupware 1.1 before 1.1.6 and 1.
The form library in Horde Application Framework 3.2 before 3.2.5 and 3.3 before 3.3.5.
Groupware 1.1 before 1.1.6 and 1.2 before 1.2.4.
and Groupware Webmail Edition 1.1 before 1.1.6 and 1.2 before 1.2.4.
reuses temporary filenames during the upload process which allows remote attackers, with privileges to write to the address book, to overwrite arbitrary files and execute PHP code via crafted Horde_Form_Type_image form field elements.
MEDIUM · CVSS 4.3
EPSS 0.00838
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0