Title : Horde Groupware Calendar Component Unspecified File Inclusion Vulnerability VUPEN ID : VUPEN/ADV-2007-0368 CVE ID : CVE-2007-0579
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-01-26
Technical Description
A vulnerability has been identified in Horde Groupware, which could be exploited by remote attackers to gain knowledge of sensitive information or potentially compromise a vulnerable server. This issue is due to an unspecified input validation error in the calendar component, which could be exploited by remote attackers to include or disclose the contents of arbitrary files with the privileges of the web server.