Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possibly gain privileges via certain database functions such as check_prefs() in db.pgsql, as demonstrated using mailbox.php3.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Imp | Horde | 2.2 (including) | 2.2 (including) |
Imp | Horde | 2.2.1 (including) | 2.2.1 (including) |
Imp | Horde | 2.2.2 (including) | 2.2.2 (including) |
Imp | Horde | 2.2.3 (including) | 2.2.3 (including) |
Imp | Horde | 2.2.4 (including) | 2.2.4 (including) |
Imp | Horde | 2.2.5 (including) | 2.2.5 (including) |
Imp | Horde | 2.2.6 (including) | 2.2.6 (including) |
Imp | Horde | 2.2.7 (including) | 2.2.7 (including) |
Imp | Horde | 2.2.8 (including) | 2.2.8 (including) |