First published: Wed Jan 15 2003(Updated: )
Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possibly gain privileges via certain database functions such as check_prefs() in db.pgsql, as demonstrated using mailbox.php3.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Horde | =2.2 | |
Horde | =2.2.1 | |
Horde | =2.2.2 | |
Horde | =2.2.3 | |
Horde | =2.2.4 | |
Horde | =2.2.5 | |
Horde | =2.2.6 | |
Horde | =2.2.7 | |
Horde | =2.2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0025 is considered a critical severity vulnerability that allows for unauthorized database access.
To fix CVE-2003-0025, upgrade to Horde IMP version 2.2.9 or later.
CVE-2003-0025 affects Horde IMP versions 2.2.0 to 2.2.8.
CVE-2003-0025 allows remote attackers to exploit SQL injection vulnerabilities present in certain database functions.
Exploitation of CVE-2003-0025 can lead to unauthorized activities in the database and potential privilege escalation.