CVE-2012-0209

Horde Groupware 1.2.10 and Horde 3.3.12 - Remote Code Execution via Trojanized JavaScript Template

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2012-0209. PoCs published by Metasploit, Eric Romang, jduck, including Metasploit module exploits/multi/http/horde_href_backdoor.

AI-analyzed exploit summary This Metasploit module exploits a backdoor in Horde 3.3.12 and Horde Groupware 1.2.10, allowing arbitrary PHP code execution via a crafted HTTP request to the `javascript.php` endpoint. The exploit leverages a malicious `Cookie` header to inject and execute payloads.

Description

Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2012, contains an externally introduced modification (Trojan Horse) in templates/javascript/open_calendar.js, which allows remote attackers to execute arbitrary PHP code.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotelinux
https://www.exploit-db.com/exploits/18492

This Metasploit module exploits a backdoor in Horde 3.3.12 and Horde Groupware 1.2.10, allowing arbitrary PHP code execution via a crafted HTTP request to the `javascript.php` endpoint. The exploit leverages a malicious `Cookie` header to inject and execute payloads.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Horde 3.3.12, Horde Groupware 1.2.10
No auth needed
Prerequisites: Target must have the vulnerable Horde version installed · The `javascript.php` endpoint must be accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Eric Romang, jduck · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/horde_href_backdoor.rb

This Metasploit module exploits a backdoor in Horde 3.3.12 and Horde Groupware 1.2.10, allowing arbitrary PHP code execution via a malicious 'href' cookie in a POST request to 'javascript.php'. The payload is executed using the 'passthru' function.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Horde 3.3.12, Horde Groupware 1.2.10
No auth needed
Prerequisites: Target must be running vulnerable Horde version · The 'app' parameter must be active
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

EPSS 0.7190
EPSS Percentile 99.3%

Details

CWE
CWE-94
Status published
Products (2)
horde/groupware 1.2.10 (2 CPE variants)
horde/horde 3.3.12
Published Sep 25, 2012
Tracked Since Feb 18, 2026