← Vulnerability feed

Vulnerability record · CVE-2007-1474 · published 16 March 2007

CVE-2007-1474: Horde application framework vulnerability

Horde · Horde Application Framework

Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows local users to delete arbitrary files and possibly gain privileges via multiple space-delimited pathnames.

6.8 CVSS 2.0 Medium EPSS 4.9% · top 8.1%
6.8CVSS 2.0 base score
4.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows local users to delete arbitrary files and possibly gain privileges via multiple space-delimited pathnames.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-1474 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2014-1691Horde application framework code injection vulnerabilityThe framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injection attac…EPSS 43%7.5CVE-2003-0025Horde imp vulnerabilityMultiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possibly gain …EPSS 28%7.5CVE-2002-0181Horde vulnerabilityCross-site scripting vulnerability in status.php3 for IMP 2.2.8 and HORDE 1.2.7 allows remote attackers to execute arbitrary web script and steal coo…EPSS 1.8%7.5CVE-2001-1257Horde imp vulnerabilityCross-site scripting vulnerability in Horde Internet Messaging Program (IMP) before 2.2.6 and 1.2.6 allows remote attackers to execute arbitrary Java…EPSS 2.0%6.8CVE-2015-7984Horde groupware cross-site request forgery vulnerabilityMultiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware Webmail Edition …EPSS 4.1%6.8CVE-2010-3694Horde application framework cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in the Horde Application Framework before 3.3.9 allows remote attackers to hijack the authentication …EPSS 0.61%6.8CVE-2004-0584Horde imp vulnerabilityUnknown vulnerability in Horde IMP 3.2.3 and earlier, before a "security fix," does not properly validate input, which allows remote attackers to exe…EPSS 1.3%5.8CVE-2007-6018Horde framework permissions and access controls vulnerabilityIMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3 does not validate unspecified HTTP requests, w…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2007-1474), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.