IMP 2.2 and earlier allows attackers to read and delete arbitrary files by modifying the attachment_name hidden form variable, which causes IMP to send the file to the attacker as an attachment.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Imp |
Horde |
2.0 |
2.0 |
Imp |
Horde |
2.2 |
2.2 |
References