← Vulnerability feed

Vulnerability record · CVE-2012-0209 · published 25 September 2012

CVE-2012-0209: Horde open_calendar.js trojan enables remote PHP code execution

Horde · Groupware

Horde 3.3.12, Horde Groupware 1.2.10 and Groupware Webmail Edition 1.2.10 distributed via FTP between November 2011 and February 2012 contained an externally introduced modification (Trojan Horse) in templates/javascript/open_calendar.js. That injected code lets remote attackers execute arbitrary PHP code, so any deployment of these FTP-distributed builds should be treated as compromised.

7.5 CVSS 2.0 High EPSS 72% · top 0.6% CWE-94 · Code injection
7.5CVSS 2.0 base score
72%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
10References, 8 tagged exploit
16 Jun 2026Last modified by NVD

Description

Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2012, contains an externally introduced modification (Trojan Horse) in templates/javascript/open_calendar.js, which allows remote attackers to execute arbitrary PHP code.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityRemote unauthenticated code execution with public exploit references and very high EPSS, though the affected builds are old and no KEV listing exists.

What it is

Horde 3.3.12, Horde Groupware 1.2.10 and Groupware Webmail Edition 1.2.10 distributed via FTP between November 2011 and February 2012 contained an externally introduced modification (Trojan Horse) in templates/javascript/open_calendar.js. That injected code lets remote attackers execute arbitrary PHP code, so any deployment of these FTP-distributed builds should be treated as compromised.

Impact

An attacker can execute arbitrary PHP code on the server, which typically leads to full compromise of the Horde host and any data it handles, including mail and groupware content.

Attack surface

The flaw is network reachable (AV:N) with no authentication or user interaction required per the CVSS vector, and is triggered through the tampered JavaScript template shipped in the affected distributions.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.71897, 99.4th percentile) and multiple references are tagged Exploit, indicating public exploit material exists.

What to do

  • Replace affected FTP-distributed Horde 3.3.12 / Groupware 1.2.10 / Webmail Edition 1.2.10 installs with clean copies from official Horde release channels and apply the vendor patch.
  • Verify integrity of templates/javascript/open_calendar.js against a trusted source and remove or restore any modified file.
  • Rebuild or reimage hosts that ran the tampered builds, since arbitrary PHP execution implies possible full compromise.
  • Restrict outbound and inbound access to the Horde web tier and review server logs for unexpected PHP execution.
  • Rotate credentials and secrets stored or processed by the affected Horde instance.

Detection

  • Compare templates/javascript/open_calendar.js hashes against known-good Horde release artifacts.
  • Monitor web server logs for requests to open_calendar.js and for anomalous PHP execution or outbound callbacks from the Horde host.
  • Scan the Horde installation for unexpected or recently modified PHP/JS files.
  • Alert on process or network activity from the web server user that is inconsistent with normal Horde operation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-0209 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-7218Horde groupware vulnerabilityUnspecified vulnerability in the Horde API in Horde 3.1 before 3.1.6 and 3.2 before 3.2 before 3.2-RC2; Turba H3 2.1 before 2.1.6 and 2.2 before 2.2-…EPSS 2.2%10.0CVE-2008-7219Horde groupware permissions and access controls vulnerabilityHorde Kronolith H3 2.1 before 2.1.7 and 2.2 before 2.2-RC2; Nag H3 2.1 before 2.1.4 and 2.2 before 2.2-RC2; Mnemo H3 2.1 before 2.1.2 and H3 2.2 befo…EPSS 2.7%10.0CVE-2005-3344Horde vulnerabilityThe default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain access.EPSS 8.0%9.8CVE-2020-8518Horde Groupware Webmail CSV import PHP code injectionHorde Groupware Webmail Edition 5.2.22 permits injection of arbitrary PHP code through CSV data, resulting in remote code execution. The flaw is a co…EPSS 72%analysed8.8CVE-2013-6364Horde groupware cross-site scripting vulnerabilityHorde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address bookEPSS 2.1%8.8CVE-2019-12095Horde groupware cross-site scripting vulnerabilityHorde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags para…EPSS 1.1%8.8CVE-2019-9858Horde groupware path traversal vulnerabilityRemote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17. Horde/Form/Type.php contains a vulnerable class that handles image…EPSS 19%8.8CVE-2017-7413Horde groupware os command injection vulnerabilityIn Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition through 5.2.17, OS Command Injection can occur if the attacker is an authenti…EPSS 40%

Source: NIST National Vulnerability Database (record CVE-2012-0209), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.