Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Horde Internet Messaging Program (IMP) before 2.2.6 allows local users to read IMP configuration files and steal the Horde database password by placing the prefs.lang file containing PHP code on the server.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Horde IMP 本地 'prefs.lang' 漏洞
Vulnerability Description
CVE(CAN) ID: CAN-2001-1258 IMP是由Horde项目组成员开发的一个强大的基于Web的邮件客户程序,Horde程序的框架 提供了对参数设置,压缩,浏览器检测,连接跟踪等功能。 如果攻击者能够在一台服务器上创建一个文件"prefs.lang",那么该文件中的内容就 会被当作PHP代码执行。 利用这个漏洞,攻击者可能以Web服务器的权限执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A