Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-6018

Опубликовано: 11 янв. 2008
Источник: nvd
CVSS2: 5.8
EPSS Низкий

Описание

IMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3 does not validate unspecified HTTP requests, which allows remote attackers to (1) delete arbitrary e-mail messages via a modified numeric ID or (2) "purge" deleted emails via a crafted email message.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:horde:framework:3.1.5:*:*:*:*:*:*:*
cpe:2.3:a:horde:groupware_webmail_edition:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:horde:horde:3.1.5:*:*:*:*:*:*:*
cpe:2.3:a:horde:imp:4.1.5:*:*:*:*:*:*:*

EPSS

Процентиль: 78%
0.0115
Низкий

5.8 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
больше 17 лет назад

IMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3 does not validate unspecified HTTP requests, which allows remote attackers to (1) delete arbitrary e-mail messages via a modified numeric ID or (2) "purge" deleted emails via a crafted email message.

redhat
больше 17 лет назад

IMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3 does not validate unspecified HTTP requests, which allows remote attackers to (1) delete arbitrary e-mail messages via a modified numeric ID or (2) "purge" deleted emails via a crafted email message.

debian
больше 17 лет назад

IMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde ...

github
больше 3 лет назад

IMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3 does not validate unspecified HTTP requests, which allows remote attackers to (1) delete arbitrary e-mail messages via a modified numeric ID or (2) "purge" deleted emails via a crafted email message.

EPSS

Процентиль: 78%
0.0115
Низкий

5.8 Medium

CVSS2

Дефекты

CWE-264