S4E just found a high-severity finding from top 38 parameters xss vulnerability scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2009-0932 Scanner

CVE-2009-0932 scanner - Remote Code Execution (RCE) vulnerability in Horde and Horde Groupware

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2009-0932
6.4
CVSS

Directory traversal vulnerability in framework/Image/Image.php in Horde before 3.2.4 and 3.3.3 and Horde Groupware before 1.1.5 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Horde_Image driver name.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Horde and Horde Groupware are popular web applications used for group collaboration and communication. The Horde framework provides a suite of web-based communications and collaboration tools, including email, calendar, tasks, and notes. Horde Groupware is an application built on top of the Horde framework and includes additional functionality such as project management and file sharing.

However, these applications are not completely secure, and they were affected by CVE-2009-0932. This vulnerability allowed remote attackers to include and execute arbitrary local files by using directory traversal sequences in the Horde_Image driver name present in the Horde_Image component. An attacker can exploit this vulnerability by appending "../" or similar characters to the file path, which allows them to access files outside the intended directory, including sensitive files that can cause significant damage.

This vulnerability can lead to data theft, data manipulation, and even total system compromise. By exploiting this vulnerability, an attacker can gain access to confidential information, such as passwords, credit card data, and private files, and can also install malicious code on the server to gain complete control. This can result in severe financial and reputational damages for the affected organization.

In conclusion, it is essential to be aware of the vulnerabilities present in our digital assets and take proactive measures to protect them. Thanks to the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets and take the appropriate actions to prevent attacks. By being proactive and vigilant, we can avoid costly and damaging security breaches.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is recommended to apply the latest security patches provided by Horde. Other precautions can include:

  • Implementing access control to restrict unauthorized access to sensitive files
  • Ensuring that the application uses the least privilege principle
  • Implementing web application firewall rules to block suspicious requests and prevent directory traversal attacks

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2009-0932 scanner - Remote Code Execution (RCE) vulnerability in Horde and Horde Groupware | S4E