5.8
CVSSv2

CVE-2007-6018

Published: 11/01/2008 Updated: 29/07/2017
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

IMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3 does not validate unspecified HTTP requests, which allows remote malicious users to (1) delete arbitrary e-mail messages via a modified numeric ID or (2) "purge" deleted emails via a crafted email message.

Vulnerable Product Search on Vulmon Subscribe to Product

horde framework 3.1.5

horde imp 4.1.5

horde groupware webmail edition 1.0.3

horde horde 3.1.5

Vendor Advisories

Ulf Härnhammar discovered that the HTML filter of the Horde web application framework performed insufficient input sanitising, which may lead to the deletion of emails if a user is tricked into viewing a malformed email inside the Imp client This update also provides backported bugfixes to the cross-site scripting filter and the user management A ...