Filtered by vendor Horde
                         Subscriptions
                    
                    
                
                        Filtered by product Imp
                         Subscriptions
                    
                    
                
                    Total
                    22 CVE
                
            | CVE | Vendors | Products | Updated | CVSS v3.1 | 
|---|---|---|---|---|
| CVE-2003-0025 | 1 Horde | 1 Imp | 2025-04-03 | N/A | 
| Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possibly gain privileges via certain database functions such as check_prefs() in db.pgsql, as demonstrated using mailbox.php3. | ||||
| CVE-2002-2024 | 1 Horde | 1 Imp | 2025-04-03 | 5.3 Medium | 
| Horde IMP 2.2.7 allows remote attackers to obtain the full web root pathname via an HTTP request for (1) poppassd.php3, (2) login.php3?reason=chpass2, (3) spelling.php3, and (4) ldap.search.php3?ldap_serv=nonsense which leaks the information in error messages. | ||||