RULE(RULE ID:321807)

Rule General Information
Release Date: 2019-06-13
Rule Name: Horde Framework PHP Object Injection Vulnerability (CVE-2014-1691)
Severity:
CVE ID:
Rule Protection Details
Description: The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injection attacks and execute arbitrary PHP code via a crafted serialized object in the _formvars form.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: http://seclists.org/oss-sec/2014/q1/153
http://seclists.org/oss-sec/2014/q1/156
http://seclists.org/oss-sec/2014/q1/169
http://www.debian.org/security/2014/dsa-2853
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://www.horde.org/