CVE Vulnerabilities

CVE-2007-6018

Published: Jan 11, 2008 | Modified: Jul 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

IMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3 does not validate unspecified HTTP requests, which allows remote attackers to (1) delete arbitrary e-mail messages via a modified numeric ID or (2) purge deleted emails via a crafted email message.

Affected Software

Name Vendor Start Version End Version
Framework Horde 3.1.5 (including) 3.1.5 (including)
Groupware_webmail_edition Horde 1.0.3 (including) 1.0.3 (including)
Horde Horde 3.1.5 (including) 3.1.5 (including)
Imp Horde 4.1.5 (including) 4.1.5 (including)
Horde3 Ubuntu dapper *
Horde3 Ubuntu devel *
Horde3 Ubuntu edgy *
Horde3 Ubuntu feisty *
Horde3 Ubuntu gutsy *
Horde3 Ubuntu hardy *
Horde3 Ubuntu intrepid *
Horde3 Ubuntu jaunty *
Horde3 Ubuntu karmic *

References