CVE-2007-1474
Last modified
CVE-2007-1474 is a vulnerability of currently unknown severity. Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows local users to delete arbitrary files and possibly gain privileges via multiple space-delimited pathnames.. EPSS estimates a 4.95% chance of exploitation in the next 30 days.
Description
Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows local users to delete arbitrary files and possibly gain privileges via multiple space-delimited pathnames.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Horde | Horde Application Framework | 3.0.0 |
| Horde | Horde Application Framework | 3.0.4 |
| Horde | Horde Application Framework | 3.1.3 |
| Horde | Imp | 2.0 |
| Horde | Imp | 2.2 |
| Horde | Imp | 2.2.1 |
| Horde | Imp | 2.2.2 |
| Horde | Imp | 2.2.3 |
| Horde | Imp | 2.2.4 |
| Horde | Imp | 2.2.5 |
| Horde | Imp | 2.2.6 |
| Horde | Imp | 2.2.7 |
| Horde | Imp | 2.2.8 |
| Horde | Imp | 2.3 |
| Horde | Imp | 3.0 |
| Horde | Imp | 3.1 |
| Horde | Imp | 3.1.2 |
| Horde | Imp | 3.2 |
| Horde | Imp | 3.2.1 |
| Horde | Imp | 3.2.2 |
| Horde | Imp | 3.2.3 |
| Horde | Imp | 3.2.4 |
| Horde | Imp | 3.2.5 |
| Horde | Imp | 3.2.6 |
References
- http://lists.horde.org/archives/announce/2007/000315.htmlPatch, Vendor Advisory
- http://lists.horde.org/archives/announce/2007/000315.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-1474?
How severe is CVE-2007-1474?
How do I fix CVE-2007-1474?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-1468Cross-site scripting (XSS) vulnerability in IBM Rational Cle…
- CVE-2007-1469SQL injection vulnerability in gallery.asp in Absolute Image…
- CVE-2007-1470Multiple buffer overflows in LIBFtp 5.0 allow user-assisted …
- CVE-2007-1471admin/default.asp in Orion-Blog 2.0 allows remote attackers …
- CVE-2007-1472Variable overwrite vulnerability in groupit/base/groupit.sta…
- CVE-2007-1473Cross-site scripting (XSS) vulnerability in framework/NLS/NL…
- CVE-2007-1475Multiple buffer overflows in the (1) ibase_connect and (2) i…
- CVE-2007-1476The SymTDI device driver (SYMTDI.SYS) in Symantec Norton Per…
- CVE-2007-1477Directory traversal vulnerability in index.php in PHP Point …
- CVE-2007-1478download.php in McGallery 0.5b allows remote attackers to re…
- CVE-2007-1479Cross-site scripting (XSS) vulnerability in Guestbook.php in…
- CVE-2007-1480Creative Guestbook 1.0 allows remote attackers to add an adm…
Are you affected by CVE-2007-1474?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
