Vulnerability record · CVE-2009-0932 · published 17 March 2009
CVE-2009-0932: Horde Image driver name path traversal allows local file inclusion
Debian · Horde
Horde and Horde Groupware fail to sanitize the Horde_Image driver name in framework/Image/Image.php, allowing directory traversal sequences to reach local files. An attacker can include and execute arbitrary local files, which can lead to code execution if a suitable file is present on the server.
Description
Directory traversal vulnerability in framework/Image/Image.php in Horde before 3.2.4 and 3.3.3 and Horde Groupware before 1.1.5 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Horde_Image driver name.
AV:N/AC:L/Au:N/C:P/I:P/A:N
Automated analysis
high priorityUnauthenticated network-reachable local file inclusion with high EPSS despite no KEV listing.
What it is
Horde and Horde Groupware fail to sanitize the Horde_Image driver name in framework/Image/Image.php, allowing directory traversal sequences to reach local files. An attacker can include and execute arbitrary local files, which can lead to code execution if a suitable file is present on the server.
Impact
An unauthenticated remote attacker can read and execute local files in the web server context, potentially leading to full compromise of the Horde host.
Attack surface
Reachable over the network through the Horde_Image driver name parameter; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is 0.45764 (98.7th percentile), indicating elevated predicted exploitation activity.
What to do
- Upgrade Horde to 3.2.4 or 3.3.3 and Horde Groupware to 1.1.5 or later.
- Apply the vendor advisories referenced in the Horde announcement lists.
- Restrict or disable unused Horde_Image drivers and validate driver names against an allowlist.
- Run Horde with least privilege and disable remote file inclusion and dangerous PHP settings where possible.
Detection
- Monitor web logs for traversal sequences such as ../ in requests to Horde image or driver parameters.
- Alert on unexpected local file inclusion attempts or PHP errors referencing framework/Image/Image.php.
- Audit file access and process execution originating from the Horde web user for anomalous paths.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-0932 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-0932), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.