← All CVEs

CVE-2014-1691

high · 7.5

The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injection attacks and execute arbitrary PHP code via a crafted serialized object in the _formvars form.

7.5
CVSS
42.9%
EPSS (exploit prob.)
99th
EPSS percentile
2014-04-01
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Weaknesses

CWE-94

Affected products

VendorProductAffected versions
hordehorde_application_framework<= 5.1.0
hordehorde_application_framework5.0.0
hordehorde_application_framework5.0.1
hordehorde_application_framework5.0.2
hordehorde_application_framework5.0.3
hordehorde_application_framework5.0.4

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-1691