HTTP: Horde Groupware Webmail Data Import PHP Code Injection
This signature detects attempts to exploit a known vulnerability against Horde Groupware Webmail. A successful attack can lead to command injection and arbitrary code execution.
Extended Description
Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution.
Affected Products
Debian debian_linux
References
CVE: CVE-2020-8518
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Horde
Fedoraproject
Debian
7.5