FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

kronolith -- arbitrary local file inclusion vulnerability

Affected packages
kronolith < 2.1.4

Details

VuXML ID a8af7d70-8007-11db-b280-0008743bf21a
Discovery 2006-11-29
Entry 2006-11-30

iDefense Labs reports:

Remote exploitation of a design error in Horde's Kronolith could allow an authenticated web mail user to execute arbitrary PHP code under the security context of the running web server.

The vulnerability specifically exists due to a design error in the way it includes certain files. Specifically, the 'lib/FBView.php' file contains a function 'Kronolith_FreeBusy_View::factory' which will include local files that are supplied via the 'view' HTTP GET request parameter.

References

URL http://lists.horde.org/archives/announce/2006/000307.html