CVE-2001-1258
https://notcve.org/view.php?id=CVE-2001-1258
Horde Internet Messaging Program (IMP) before 2.2.6 allows local users to read IMP configuration files and steal the Horde database password by placing the prefs.lang file containing PHP code on the server. • http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000410 http://online.securityfocus.com/archive/1/198495 http://www.caldera.com/support/security/advisories/CSSA-2001-027.0.txt http://www.debian.org/security/2001/dsa-073 http://www.iss.net/security_center/static/6906.php http://www.securityfocus.com/bid/3083 •
CVE-2001-1257
https://notcve.org/view.php?id=CVE-2001-1257
Cross-site scripting vulnerability in Horde Internet Messaging Program (IMP) before 2.2.6 and 1.2.6 allows remote attackers to execute arbitrary Javascript embedded in an email. • http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000410 http://online.securityfocus.com/archive/1/198495 http://www.caldera.com/support/security/advisories/CSSA-2001-027.0.txt http://www.debian.org/security/2001/dsa-073 http://www.iss.net/security_center/static/6905.php http://www.securityfocus.com/bid/3082 •
CVE-2000-0910
https://notcve.org/view.php?id=CVE-2000-0910
Horde library 1.02 allows attackers to execute arbitrary commands via shell metacharacters in the "from" address. • http://archives.neohapsis.com/archives/bugtraq/2000-09/0051.html http://ssl.coc-ag.de/sec/hordelib-1.2.0.frombug.patch http://www.debian.org/security/2000/20000910 http://www.securityfocus.com/bid/1674 https://exchange.xforce.ibmcloud.com/vulnerabilities/5278 •
CVE-2000-0911
https://notcve.org/view.php?id=CVE-2000-0911
IMP 2.2 and earlier allows attackers to read and delete arbitrary files by modifying the attachment_name hidden form variable, which causes IMP to send the file to the attacker as an attachment. • http://www.securityfocus.com/archive/1/82088 http://www.securityfocus.com/bid/1679 https://exchange.xforce.ibmcloud.com/vulnerabilities/5227 •