CVE-2000-0911: Medium severity Horde IMP vulnerability
Published Dec 19, 2000
·Updated
IMP 2.2 and earlier allows attackers to read and delete arbitrary files by modifying the attachmentname hidden form variable, which causes IMP to send the file to the attacker as an attachment.
Affected Software
2 affected components
Horde IMP=2.0
Horde IMP=2.2
Remediation
Patch Available
Patch Available
Event History
Dec 19, 2000
CVE Published
05:00 AM
Jan 22, 2001
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-0911?
The severity of CVE-2000-0911 is considered high due to the potential for arbitrary file reading and deletion.
2
How do I fix CVE-2000-0911?
To fix CVE-2000-0911, upgrade to at least Horde IMP version 2.3 or higher where this vulnerability is patched.
3
What versions of Horde IMP are affected by CVE-2000-0911?
Horde IMP versions 2.0 and 2.2 are affected by CVE-2000-0911.
4
What types of attacks can CVE-2000-0911 facilitate?
CVE-2000-0911 can facilitate attacks allowing attackers to read and delete arbitrary files on the server.
5
Is CVE-2000-0911 a client-side or server-side vulnerability?
CVE-2000-0911 is a server-side vulnerability that affects the handling of attachments in the Horde IMP application.