First published: Thu Jan 10 2008(Updated: )
IMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3 does not validate unspecified HTTP requests, which allows remote attackers to (1) delete arbitrary e-mail messages via a modified numeric ID or (2) "purge" deleted emails via a crafted email message.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Horde | =3.1.5 | |
Horde Horde application framework | =3.1.5 | |
Horde Groupware | =1.0.3 | |
Horde | =4.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6018 is considered a high severity vulnerability due to its potential to allow remote attackers to delete arbitrary emails.
To fix CVE-2007-6018, update to the latest versions of IMP Webmail Client, Horde Application Framework, or Horde Groupware Webmail Edition that address this issue.
The affected software versions for CVE-2007-6018 include IMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3.
Yes, CVE-2007-6018 can lead to data loss due to its ability to delete emails remotely.
No, exploitation of CVE-2007-6018 does not require authentication, making it particularly concerning.