Horde arbitrary file inclusion vulnerability
Posted on March 7th, 2008 by Gabriel Harper in Servers & Security, Software & ScriptsAdmins running cPanel w/ Horde should pay special attention to the security update released by cPanel. An arbitrary file inclusion vulnerability was discovered in the Horde webmail app and a patch is included in cPanel builds 11.18.2+ (11.19.2+ for EDGE).
Update cPanel with WHM or as root:
/scripts/upcp
For more info read the official announcement.