module

Horde 3.3.12 Backdoor Arbitrary PHP Code Execution

Disclosed
2012-02-13
Created
2018-05-30

Description

This module exploits an arbitrary PHP code execution vulnerability introduced
as a backdoor into Horde 3.3.12 and Horde Groupware 1.2.10.

Authors

Eric Romang
jduck jduck@metasploit.com

Platform

Linux,Unix

Architectures

cmd

Module Options

To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:


msf > use exploit/multi/http/horde_href_backdoor
msf exploit(horde_href_backdoor) > show targets
...targets...
msf exploit(horde_href_backdoor) > set TARGET < target-id >
msf exploit(horde_href_backdoor) > show options
...show and set options...
msf exploit(horde_href_backdoor) > exploit

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.