CVE-2001-1257: High severity Horde IMP vulnerability
Published Jul 21, 2001
·Updated
Cross-site scripting vulnerability in Horde Internet Messaging Program (IMP) before 2.2.6 and 1.2.6 allows remote attackers to execute arbitrary Javascript embedded in an email.
Affected Software
7 affected components
Horde IMP=2.2.5
Horde IMP=2.2.1
Horde IMP=2.2.2
Horde IMP=2.2.4
Horde IMP=2.0
Horde IMP=2.2
Horde IMP=2.2.3
Remediation
Patch Available
Event History
Jul 21, 2001
CVE Published
04:00 AM
May 3, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1257?
CVE-2001-1257 is considered a high severity cross-site scripting vulnerability allowing execution of arbitrary JavaScript.
2
How does CVE-2001-1257 affect users of Horde IMP?
CVE-2001-1257 allows remote attackers to execute malicious JavaScript on the client side, potentially compromising user data.
3
How do I fix CVE-2001-1257?
To fix CVE-2001-1257, upgrade to Horde IMP version 2.2.6 or 1.2.6 or later.
4
Which versions of Horde IMP are affected by CVE-2001-1257?
CVE-2001-1257 affects Horde IMP versions prior to 2.2.6 and 1.2.6, including 2.2.5 and 2.2.1.
5
What type of attack is enabled by CVE-2001-1257?
CVE-2001-1257 enables cross-site scripting attacks through email, allowing execution of embedded JavaScript.