Unrated severityNVD Advisory· Published Dec 31, 2002· Updated Apr 16, 2026
CVE-2002-2165
CVE-2002-2165
Description
The IMHO Webmail module 0.97.3 and earlier for Roxen leaks the REFERER from the browser's previous login session in an error page, which allows local users to read another user's inbox.
Affected products
9cpe:2.3:a:imho:imho_webmail:0.96:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:imho:imho_webmail:0.96:*:*:*:*:*:*:*
- cpe:2.3:a:imho:imho_webmail:0.96.1:*:*:*:*:*:*:*
- cpe:2.3:a:imho:imho_webmail:0.96.2:*:*:*:*:*:*:*
- cpe:2.3:a:imho:imho_webmail:0.96.3:*:*:*:*:*:*:*
- cpe:2.3:a:imho:imho_webmail:0.97:*:*:*:*:*:*:*
- cpe:2.3:a:imho:imho_webmail:0.97.1:*:*:*:*:*:*:*
- cpe:2.3:a:imho:imho_webmail:0.98:*:*:*:*:*:*:*
- cpe:2.3:a:imho:imho_webmail:0.98.2:*:*:*:*:*:*:*
- cpe:2.3:a:imho:imho_webmail:0.98.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.securityfocus.com/bid/5238nvdExploit
- www.securitybugware.org/Other/5537.htmlnvdVendor Advisory
- www.iss.net/security_center/static/9615.phpnvd
News mentions
0No linked articles in our index yet.