First published: Wed Sep 03 2003(Updated: )
Horde before 2.2.4 allows remote malicious web sites to steal session IDs and read or create arbitrary email by stealing the ID from a referrer URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Horde | <=2.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0728 is considered a moderate severity vulnerability due to the potential for session hijacking.
To fix CVE-2003-0728, upgrade Horde to version 2.2.4 or later.
CVE-2003-0728 allows remote attackers to steal session IDs, leading to unauthorized access to email.
Horde versions before 2.2.4 are affected by CVE-2003-0728.
Yes, CVE-2003-0728 can compromise user data by allowing attackers to read or create arbitrary emails.