3 results (0.002 seconds)

CVSS: 7.5EPSS: 7%CPEs: 1EXPL: 1

06 Dec 2001 — Cross-site scripting vulnerability in status.php3 in Imp Webmail 2.2.6 and earlier allows remote attackers to gain access to the e-mail of other users by hijacking session cookies via the message parameter. • https://www.exploit-db.com/exploits/21151 •

CVSS: 5.5EPSS: 0%CPEs: 5EXPL: 0

22 Apr 2000 — The MSWordView application in IMP creates world-readable files in the /tmp directory, which allows other local users to read potentially sensitive information. • http://marc.info/?l=bugtraq&m=95672120116627&w=2 •

CVSS: 5.5EPSS: 0%CPEs: 7EXPL: 0

22 Apr 2000 — IMP does not remove files properly if the MSWordView application quits, which allows local users to cause a denial of service by filling up the disk space by requesting a large number of documents and prematurely stopping the request. • http://marc.info/?l=bugtraq&m=95672120116627&w=2 •