PT-2001-2390 · Horde · Horde Internet Messaging Program

Published

2001-07-21

·

Updated

2011-03-08

·

CVE-2001-1258

CVSS v2.0

3.6

Low

VectorAV:L/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Horde Internet Messaging Program (IMP) versions prior to 2.2.6
Description: The issue allows local users to read IMP configuration files, potentially stealing the Horde database password. This is achieved by placing a prefs.lang file containing PHP code on the server.
Recommendations: For versions prior to 2.2.6, update to version 2.2.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the prefs.lang file and the IMP configuration files to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-1258

Affected Products

Horde Internet Messaging Program