Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-1474. PoCs published by anonymous.
AI-analyzed exploit summary The exploit describes a vulnerability in Horde Framework and IMP where a local attacker can delete arbitrary files by creating a specially crafted file and running the affected cron script. This results in the deletion of specified files, including critical system files like '/etc/passwd'.
Description
Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows local users to delete arbitrary files and possibly gain privileges via multiple space-delimited pathnames.
Exploits (1)
The exploit describes a vulnerability in Horde Framework and IMP where a local attacker can delete arbitrary files by creating a specially crafted file and running the affected cron script. This results in the deletion of specified files, including critical system files like '/etc/passwd'.