REDHAT-BUG-428625: High severity horde imp vulnerability
Common Vulnerabilities and Exposures assigned an identifier CVE-2007-6018 to the following vulnerability:
IMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3 does not validate unspecified HTTP requests, which allows remote attackers to (1) delete arbitrary e-mail messages via a modified numeric ID or (2) "purge" deleted emails via a crafted email message.
References:
http://secunia.com/secuniaresearch/2007-102/advisory/ http://www.securityfocus.com/bid/27223 http://secunia.com/advisories/28020
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-428625?
The severity of REDHAT-BUG-428625 is classified as high due to its potential impact on the affected software.
How do I fix REDHAT-BUG-428625?
To fix REDHAT-BUG-428625, update to the latest patched version of IMP Webmail Client, Horde Application Framework, or Horde Groupware Webmail Edition.
What versions are affected by REDHAT-BUG-428625?
REDHAT-BUG-428625 affects IMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3.
What type of vulnerability is REDHAT-BUG-428625?
REDHAT-BUG-428625 is a web application vulnerability that does not properly validate unspecifiable input.
Is there a public exploit for REDHAT-BUG-428625?
Yes, there are reported exploits that can potentially take advantage of the vulnerabilities present in REDHAT-BUG-428625.