2.1
CVSSv2

CVE-2002-2165

Published: 31/12/2002 Updated: 05/09/2008
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 215
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The IMHO Webmail module 0.97.3 and previous versions for Roxen leaks the REFERER from the browser's previous login session in an error page, which allows local users to read another user's inbox.

Vulnerable Product Search on Vulmon Subscribe to Product

imho imho webmail 0.96

imho imho webmail 0.96.1

imho imho webmail 0.98

imho imho webmail 0.98.2

imho imho webmail 0.98.3

imho imho webmail 0.96.2

imho imho webmail 0.97

imho imho webmail 0.96.3

imho imho webmail 0.97.1

Exploits

source: wwwsecurityfocuscom/bid/5238/info A vulnerability has been reported in the IMHO Roxen webmail module which may enable a malicious user of the webmail system to gain access to the account of another user This issue is due to an error in configuration which may leak the REFERER for a session with the webmail system, which an attack ...