Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2008-1284

21
FAUCET Score

CVE-2008-1284 is a directory traversal vulnerability affecting Horde 3.1.6, Groupware before 1.0.5, and Groupware Webmail Edition before 1.0.6. This flaw allows authenticated attackers to read and execute arbitrary files by manipulating theme names with directory traversal sequences and a null byte. With a CVSS score of 6.0, it presents a medium severity risk, requiring authentication and moderate attack complexity, leading to potential partial confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, nor are public exploit codes like Metasploit or ExploitDB available, though it has garnered significant community discussion with 10 mentions.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.0.4CPE matchmatch criteria
cpe:2.3:a:horde:groupware:*:*:*:*:*:*:*:*
<= 1.0.5CPE matchmatch criteria
cpe:2.3:a:horde:groupware_webmail_edition:*:*:*:*:*:*:*:*
3.1.6CPE matchmatch criteria
cpe:2.3:a:horde:horde:3.1.6:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.0MEDIUM

AV:N/AC:M/Au:S/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
SINGLE
Exploitability Score
6.8
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
1.68%
Probability of exploitation in next 30 days
EPSS Percentile
74.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0168 is in the 78th percentile among its peer group of 1,428 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2008-1284

horde: arbitrary file inclusion through abuse of the theme preference

References

lists.horde.org / archives/announce/2008/000382.html
Patch
lists.horde.org / archives/announce/2008/000383.html
lists.horde.org / archives/announce/2008/000384.html
secunia.com / advisories/29286
Vendor Advisory
secunia.com / advisories/29374
Vendor Advisory
secunia.com / advisories/29400
Vendor Advisory
secunia.com / advisories/30047
Vendor Advisory
security.gentoo.org / glsa/glsa-200805-01.xml
securityreason.com / securityalert/3726
exchange.xforce.ibmcloud.com / vulnerabilities/41054
redhat.com / archives/fedora-package-announce/2008-March/msg00253.html
redhat.com / archives/fedora-package-announce/2008-March/msg00301.html
debian.org / security/2008/dsa-1519
securityfocus.com / archive/1/489239/100/0/threaded
securityfocus.com / archive/1/489289/100/0/threaded
securityfocus.com / bid/28153
Patch
vupen.com / english/advisories/2008/0822/references