Horde Framework and IMP Cleanup Cron Script Arbitrary File Deletion Vulnerability

An attacker could exploit this issue by creating a file '/tmp/x /etc/passwd /tmpmswordx' and running the affected cron script. This will result in the deletion of '/tmp/x', '/etc/passwd', and '/tmp/mswordx'.


 

Privacy Statement
Copyright 2010, SecurityFocus