3.6
CVSSv2

CVE-2001-1258

Published: 21/07/2001 Updated: 08/03/2011
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Horde Internet Messaging Program (IMP) prior to 2.2.6 allows local users to read IMP configuration files and steal the Horde database password by placing the prefs.lang file containing PHP code on the server.

Vulnerable Product Search on Vulmon Subscribe to Product

horde imp 2.0

horde imp 2.2

horde imp 2.2.5

horde imp 2.2.3

horde imp 2.2.4

horde imp 2.2.1

horde imp 2.2.2