The IMHO Webmail module 0.97.3 and earlier for Roxen leaks the REFERER from the browser's previous login session in an error page, which allows local users to read another user's inbox.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2002-2144 | The IMHO Webmail module 0.97.3 and earlier for Roxen leaks the REFERER from the browser's previous login session in an error page, which allows local users to read another user's inbox. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T23:40:38.467Z
Reserved: 2005-11-16T00:00:00Z
Link: CVE-2002-2165
No data.
Status : Deferred
Published: 2002-12-31T05:00:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2002-2165
No data.
OpenCVE Enrichment
No data.
EUVD