CVE-2002-2024: Medium severity Horde IMP vulnerability
Published Dec 31, 2002
·Updated
Horde IMP 2.2.7 allows remote attackers to obtain the full web root pathname via an HTTP request for (1) poppassd.php3, (2) login.php3?reason=chpass2, (3) spelling.php3, and (4) ldap.search.php3?ldapserv=nonsense which leaks the information in error messages.
Affected Software
1 affected component
Horde IMP=2.2.7
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityWeaknessAffected Software
Jul 14, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-2024?
CVE-2002-2024 is classified as a moderate vulnerability due to its potential for directory traversal.
2
How do I fix CVE-2002-2024?
To mitigate CVE-2002-2024, upgrade to Horde IMP version 2.2.8 or later, which addresses this issue.
3
What information is leaked by CVE-2002-2024?
CVE-2002-2024 allows attackers to obtain the full web root pathname through specific HTTP requests.
4
Which versions of Horde IMP are affected by CVE-2002-2024?
CVE-2002-2024 specifically affects Horde IMP version 2.2.7.
5
Can CVE-2002-2024 be exploited remotely?
Yes, CVE-2002-2024 can be exploited remotely, allowing attackers to obtain sensitive information.