Unrated severityNVD Advisory· Published Jan 11, 2008· Updated Apr 23, 2026
CVE-2007-6018
CVE-2007-6018
Description
IMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3 does not validate unspecified HTTP requests, which allows remote attackers to (1) delete arbitrary e-mail messages via a modified numeric ID or (2) "purge" deleted emails via a crafted email message.
Affected products
4- cpe:2.3:a:horde:framework:3.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:horde:groupware_webmail_edition:1.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:horde:horde:3.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:horde:imp:4.1.5:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
19- www.securityfocus.com/bid/27223nvdPatch
- secunia.com/advisories/28020nvdVendor Advisory
- secunia.com/secunia_research/2007-102/advisory/nvdVendor Advisory
- cvs.horde.org/diff.php/groupware/docs/groupware/CHANGESnvd
- cvs.horde.org/diff.php/groupware/docs/webmail/CHANGESnvd
- lists.horde.org/archives/announce/2008/000360.htmlnvd
- lists.horde.org/archives/announce/2008/000365.htmlnvd
- lists.horde.org/archives/announce/2008/000366.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.htmlnvd
- secunia.com/advisories/28546nvd
- secunia.com/advisories/29184nvd
- secunia.com/advisories/29185nvd
- secunia.com/advisories/29186nvd
- secunia.com/advisories/34418nvd
- www.debian.org/security/2008/dsa-1470nvd
- bugzilla.redhat.com/show_bug.cginvd
- exchange.xforce.ibmcloud.com/vulnerabilities/39595nvd
- www.redhat.com/archives/fedora-package-announce/2008-February/msg00888.htmlnvd
- www.redhat.com/archives/fedora-package-announce/2008-February/msg00927.htmlnvd
News mentions
0No linked articles in our index yet.