Vulnerabilities > CVE-2002-2165 - Unspecified vulnerability in Imho Webmail

047910
CVSS 2.1 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
local
low complexity
imho
exploit available

Summary

The IMHO Webmail module 0.97.3 and earlier for Roxen leaks the REFERER from the browser's previous login session in an error page, which allows local users to read another user's inbox.

Exploit-Db

descriptionIMHO Webmail 0.9x Account Hijacking Vulnerability. CVE-2002-2165. Webapps exploit for cgi platform
idEDB-ID:21617
last seen2016-02-02
modified2002-07-15
published2002-07-15
reporterSecurity Bugware
sourcehttps://www.exploit-db.com/download/21617/
titleIMHO Webmail 0.9x Account Hijacking Vulnerability