Looking for the vulnerability index of Invicti's legacy products?
Horde Imp Unauthenticated Remote Command Execution - Vulnerability Database

Horde Imp Unauthenticated Remote Command Execution

Description

The IMP is a web-based mail client for IMAP and POP3 accounts. It is built atop the Horde Application Framework, which is a general-purpose web application library written in PHP.

A vulnerability in Horde IMP could allow unauthenticated command execution via imap_open in an exposed debug page.

Remediation

The IMP debug page (accessible at <strong><span class="bb-dark">http://example.com/horde/imp/test.php</span></strong>) should be deleted after installation.

Related Vulnerabilities