The default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain access.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/24576 | vdb entry |
http://www.securityfocus.com/bid/15337/ | patch vdb entry |
http://www.networkscanning.com/Horde-Default-Admin-Password-Vulnerability-VSS_20171.html | |
http://www.osvdb.org/24117 | vdb entry |
http://www.debian.org/security/2005/dsa-884 | patch vendor advisory |