CVE-2009-0932

NUCLEI

Horde < 3.2.4 and 3.3.3 and Horde Groupware < 1.1.5 - Remote Code Execution via Image Driver Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-0932. PoCs published by skysbsb. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit demonstrates a local file inclusion vulnerability in Horde's Horde_Image::factory method, allowing unauthenticated attackers to read arbitrary files or execute PHP code via the 'driver' argument. The PoC provides a URL to exploit the vulnerability by traversing directories to access /etc/passwd.

Description

Directory traversal vulnerability in framework/Image/Image.php in Horde before 3.2.4 and 3.3.3 and Horde Groupware before 1.1.5 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Horde_Image driver name.

Exploits (1)

exploitdb WORKING POC VERIFIED
by skysbsb · textwebappsphp
https://www.exploit-db.com/exploits/16154

This exploit demonstrates a local file inclusion vulnerability in Horde's Horde_Image::factory method, allowing unauthenticated attackers to read arbitrary files or execute PHP code via the 'driver' argument. The PoC provides a URL to exploit the vulnerability by traversing directories to access /etc/passwd.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Horde 3.3.2, Horde Groupware, Horde Groupware Webmail Edition
No auth needed
Prerequisites: Target running vulnerable Horde version · Access to the 'barcode.php' endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Horde/Horde Groupware - Local File Inclusion
MEDIUMby pikpikcu

References (12)

Core 12
Core References
Vendor Advisory mailing-list x_refsource_mlist
http://lists.horde.org/archives/announce/2009/000486.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/33491
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33695
Vendor Advisory mailing-list x_refsource_mlist
http://lists.horde.org/archives/announce/2009/000483.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34418
Vendor Advisory mailing-list x_refsource_mlist
http://lists.horde.org/archives/announce/2009/000482.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34609
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/8077

Scores

EPSS 0.0561
EPSS Percentile 90.6%

Details

CWE
CWE-22
Status published
Products (10)
debian/horde 3.2
debian/horde 3.2.2
debian/horde 3.2.3
debian/horde 3.3
debian/horde 3.3.1
debian/horde 3.3.2
debian/horde_groupware 1.1.1
debian/horde_groupware 1.1.2
debian/horde_groupware 1.1.3
debian/horde_groupware 1.1.4
Published Mar 17, 2009
Tracked Since Feb 18, 2026