CVE-2015-7984

Horde Groupware < 5.2.11 - Cross-Site Request Forgery via Admin Shell Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-7984. PoCs published by High-Tech Bridge SA.

AI-analyzed exploit summary The exploit demonstrates three CSRF vulnerabilities in Horde Groupware, allowing arbitrary command execution, SQL query execution, and PHP code execution via crafted HTML forms. The PoC includes specific endpoints and payloads for each vulnerability.

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware Webmail Edition before 5.2.11 allow remote attackers to hijack the authentication of administrators for requests that execute arbitrary (1) commands via the cmd parameter to admin/cmdshell.php, (2) SQL queries via the sql parameter to admin/sqlshell.php, or (3) PHP code via the php parameter to admin/phpshell.php.

Exploits (1)

exploitdb WORKING POC
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/38765

The exploit demonstrates three CSRF vulnerabilities in Horde Groupware, allowing arbitrary command execution, SQL query execution, and PHP code execution via crafted HTML forms. The PoC includes specific endpoints and payloads for each vulnerability.

Classification
Working Poc 100%
Attack Type
Rce | Sqli | Other
Complexity
Trivial
Reliability
Reliable
Target: Horde Groupware 5.2.10 and prior
Auth required
Prerequisites: Admin session active in the target application · Victim must visit a malicious page
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Vendor Advisory mailing-list x_refsource_mlist
http://lists.horde.org/archives/announce/2015/001124.html
Vendor Advisory mailing-list x_refsource_mlist
http://lists.horde.org/archives/announce/2015/001138.html
Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/38765/
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2015/dsa-3391
Vendor Advisory mailing-list x_refsource_mlist
http://lists.horde.org/archives/announce/2015/001137.html

Scores

EPSS 0.0412
EPSS Percentile 89.5%

Details

CWE
CWE-352
Status published
Products (3)
debian/debian_linux 8.0
horde/groupware 5.0.0 - 5.2.11 (2 CPE variants)
horde/horde_application_framework 5.0.0 - 5.2.8
Published Nov 19, 2015
Tracked Since Feb 18, 2026