Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows local users to delete arbitrary files and possibly gain privileges via multiple space-delimited pathnames.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Horde Framework/IMP任意文件删除漏洞
Vulnerability Description
Horde Framework是个以PHP为基础的架构,用来创建网络应用程式;IMP是一款由Horde项目组开发的基于Web的邮件程序。 Horde的项目组的Horde和IMP的代码没有正确处理参数数据,本地攻击者可能利用此漏洞删除任意系统文件。 Horde和IMP没有正确地处理find(1)执行的输出,将find(1)的输出直接做为Y值传送给了"for X in Y; do"。由于Y值是由空格划界的,因此for循环会将路径中包含有空格的文件处理为分隔文件,这样攻击者就可以通过包含有空格的文件路径控制fi
CVSS Information
N/A
Vulnerability Type
N/A