Show filters
13 Total Results
Displaying 11-13 of 13
Sort by:
Attacker Value
Unknown

CVE-2003-0025

Disclosure Date: January 17, 2003 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possibly gain privileges via certain database functions such as check_prefs() in db.pgsql, as demonstrated using mailbox.php3.
0
Attacker Value
Unknown

CVE-2001-1257

Disclosure Date: July 21, 2001 (last updated February 22, 2025)
Cross-site scripting vulnerability in Horde Internet Messaging Program (IMP) before 2.2.6 and 1.2.6 allows remote attackers to execute arbitrary Javascript embedded in an email.
0
Attacker Value
Unknown

CVE-2001-1258

Disclosure Date: July 21, 2001 (last updated February 22, 2025)
Horde Internet Messaging Program (IMP) before 2.2.6 allows local users to read IMP configuration files and steal the Horde database password by placing the prefs.lang file containing PHP code on the server.
0