Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Horde Subscribe
Filtered by product Imp
Total 21 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-2024 1 Horde 1 Imp 2008-09-05 5.0 MEDIUM N/A
Horde IMP 2.2.7 allows remote attackers to obtain the full web root pathname via an HTTP request for (1) poppassd.php3, (2) login.php3?reason=chpass2, (3) spelling.php3, and (4) ldap.search.php3?ldap_serv=nonsense which leaks the information in error messages.