CVE-2003-0728: Medium severity Horde HORDE vulnerability
Published Sep 3, 2003
·Updated
Horde before 2.2.4 allows remote malicious web sites to steal session IDs and read or create arbitrary email by stealing the ID from a referrer URL.
Affected Software
1 affected component
Horde HORDE<=2.2.4
Event History
Sep 3, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Oct 20, 2003
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0728?
CVE-2003-0728 is considered a moderate severity vulnerability due to the potential for session hijacking.
2
How do I fix CVE-2003-0728?
To fix CVE-2003-0728, upgrade Horde to version 2.2.4 or later.
3
What types of attacks are possible with CVE-2003-0728?
CVE-2003-0728 allows remote attackers to steal session IDs, leading to unauthorized access to email.
4
Which versions of Horde are affected by CVE-2003-0728?
Horde versions before 2.2.4 are affected by CVE-2003-0728.
5
Can CVE-2003-0728 affect user data?
Yes, CVE-2003-0728 can compromise user data by allowing attackers to read or create arbitrary emails.