CVE-2012-0209 is a supply chain compromise affecting Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, distributed via the Horde FTP server between November 2011 and February 2012. An attacker gained access to the Horde FTP server and inserted a backdoor into the templates/javascript/open_calendar.js file. The backdoor allows unauthenticated remote execution of arbitrary PHP code via a crafted POST request to /services/javascript.php with specific parameters and a malicious 'href' cookie. The compromise does not affect Horde 4 or code obtained from CVS/Git repositories.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module (modules/exploits/multi/http/horde_href_backdoor.rb) that exploits a backdoor in Horde 3.3.12 and Horde Groupware 1.2.10 (CVE-2012-0209). The exploit leverages a maliciously introduced backdoor in the 'javascript.php' file, allowing arbitrary PHP code execution via a specially crafted HTTP POST request. The module sends a request to the '/horde/services/javascript.php' endpoint, setting a crafted 'href' cookie that triggers the backdoor to execute attacker-supplied commands using PHP's 'passthru' function. The exploit is operational, providing command execution on the target server. The module is written in Ruby and is designed to be used within the Metasploit framework. The only file in the repository is the exploit module itself, and it requires the attacker to specify the path to the Horde installation and the active app parameter. No hardcoded IPs or domains are present; the endpoints are relative to the target server's Horde installation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.