First published: Mon Jan 14 2008(Updated: )
Common Vulnerabilities and Exposures assigned an identifier <a href="https://access.redhat.com/security/cve/CVE-2007-6018">CVE-2007-6018</a> to the following vulnerability: IMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3 does not validate unspecified HTTP requests, which allows remote attackers to (1) delete arbitrary e-mail messages via a modified numeric ID or (2) "purge" deleted emails via a crafted email message. References: <a href="http://secunia.com/secunia_research/2007-102/advisory/">http://secunia.com/secunia_research/2007-102/advisory/</a> <a href="http://www.securityfocus.com/bid/27223">http://www.securityfocus.com/bid/27223</a> <a href="http://secunia.com/advisories/28020">http://secunia.com/advisories/28020</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Horde IMP | ||
Horde | ||
Horde Groupware Webmail Edition |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-428625 is classified as high due to its potential impact on the affected software.
To fix REDHAT-BUG-428625, update to the latest patched version of IMP Webmail Client, Horde Application Framework, or Horde Groupware Webmail Edition.
REDHAT-BUG-428625 affects IMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3.
REDHAT-BUG-428625 is a web application vulnerability that does not properly validate unspecifiable input.
Yes, there are reported exploits that can potentially take advantage of the vulnerabilities present in REDHAT-BUG-428625.