packetstormsecurity.com
http://packetstormsecurity.com/files/156872/Horde-5.2.22-CSV-Import-Code-Execution.html CVE-2020-8518
CRITICAL
Horde Groupware Webmail Edition 5.2.22 - Remote Code Execution
Record summary
CVE-2020-8518 has a selected CVSS score of 9.8 (critical); EIP currently links 2 catalogued exploits.
Description
Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBHorde Groupware Webmail Edition 5.2.22 - Remote Code ExecutionExploitDB exploitby Andrea CardaciNot analyzed1 file
MetasploitHorde CSV import arbitrary PHP code executionMetasploit exploitby Andrea Cardaci <cyrus.and@gmail.com>Not analyzed1 file
References
8[debian-lts-announce] 20200415 [SECURITY] [DLA 2174-1] php-horde-data security updatemailing list
https://lists.debian.org/debian-lts-announce/2020/04/msg00008.html FEDORA-2020-0248ad925eVendor advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2PRPIFQDGYPQ3F2TF2ETPIL7IYNSVVZQ FEDORA-2020-1e7cc91d55Vendor advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DKTNYDBDVJNMVC7QPXQI7CMPLX3USZ2T lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2PRPIFQDGYPQ3F2TF2ETPIL7IYNSVVZQ lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DKTNYDBDVJNMVC7QPXQI7CMPLX3USZ2T lists.horde.orgConfirmation
https://lists.horde.org/archives/announce/2020/001285.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-8518