CVE-2012-0209

high
Published 2012-09-25 · Modified 2026-04-29
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2012, contains an externally introduced modification (Trojan Horse) in templates/javascript/open_calendar.js, which allows remote attackers to execute arbitrary PHP code.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: security@debian.org — https://bugzilla.redhat.com/show_bug.cgi?id=790877

vendor Authored 2026-05-27

Vendor advisory: security@debian.org — http://lists.horde.org/archives/announce/2012/000751.html

vendor Authored 2026-05-27

Vendor advisory: security@debian.org — http://dev.horde.org/h/jonah/stories/view.php?channel_id=1&id=155

Application impact

VendorProductVersionsFixed
hordegroupware1.2.10
hordehorde3.3.12

References

CWEs

CWE-94

Verify integrity in audit chain (admin only). AS-IS.