Horde Internet Messaging Program (IMP) before 2.2.6 allows local users to read IMP configuration files and steal the Horde database password by placing the prefs.lang file containing PHP code on the server.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2002-05-03T04:00:00

Updated: 2024-08-08T04:51:08.211Z

Reserved: 2002-05-01T00:00:00

Link: CVE-2001-1258

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2001-07-21T04:00:00.000

Modified: 2011-03-08T02:07:04.610

Link: CVE-2001-1258

cve-icon Redhat

No data.