PT-2001-2390 · Horde · Horde Internet Messaging Program
Published
2001-07-21
·
Updated
2011-03-08
·
CVE-2001-1258
CVSS v2.0
3.6
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Horde Internet Messaging Program (IMP) versions prior to 2.2.6
Description:
The issue allows local users to read IMP configuration files, potentially stealing the Horde database password. This is achieved by placing a prefs.lang file containing PHP code on the server.
Recommendations:
For versions prior to 2.2.6, update to version 2.2.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the prefs.lang file and the IMP configuration files to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Horde Internet Messaging Program