CVE-2002-0181: High severity Horde IMP vulnerability
Published Apr 22, 2002
·Updated
Cross-site scripting vulnerability in status.php3 for IMP 2.2.8 and HORDE 1.2.7 allows remote attackers to execute arbitrary web script and steal cookies of other IMP/HORDE users via the script parameter.
Affected Software
2 affected components
Horde IMP=2.2.8
Horde HORDE=1.2.7
Remediation
Patch Available
Event History
Apr 22, 2002
CVE Published
04:00 AM
Apr 2, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0181?
CVE-2002-0181 is considered a moderate severity cross-site scripting vulnerability.
2
How do I fix CVE-2002-0181?
To fix CVE-2002-0181, upgrade to IMP version 2.2.9 or later and Horde version 1.2.8 or later.
3
What is the impact of CVE-2002-0181?
CVE-2002-0181 allows remote attackers to execute arbitrary web scripts and potentially steal cookies from other users leading to session hijacking.
4
Which software versions are affected by CVE-2002-0181?
CVE-2002-0181 affects IMP version 2.2.8 and Horde version 1.2.7.
5
Can CVE-2002-0181 be exploited remotely?
Yes, CVE-2002-0181 can be exploited remotely by attackers sending crafted requests.