CVE Vulnerabilities

CVE-2001-1258

Published: Jul 21, 2001 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.6 LOW
AV:L/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Horde Internet Messaging Program (IMP) before 2.2.6 allows local users to read IMP configuration files and steal the Horde database password by placing the prefs.lang file containing PHP code on the server.

Affected Software

NameVendorStart VersionEnd Version
ImpHorde2.0 (including)2.0 (including)
ImpHorde2.2 (including)2.2 (including)
ImpHorde2.2.1 (including)2.2.1 (including)
ImpHorde2.2.2 (including)2.2.2 (including)
ImpHorde2.2.3 (including)2.2.3 (including)
ImpHorde2.2.4 (including)2.2.4 (including)
ImpHorde2.2.5 (including)2.2.5 (including)

References