Horde 1.2.x/2.1.3 and Imp 2.2.x/3.1.2 - File Disclosure

Author: Caldera Open Linux
type: remote
platform: linux
port: 
date_added: 2001-07-13  
date_updated: 2012-09-02  
verified: 1  
codes: OSVDB-88580  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 21019.txt  
source: https://www.securityfocus.com/bid/3067/info

A vulnerability has been discovered in Horde Imp which may allow an attacker to access arbitrary system files. The issue occurs due to insufficient sanity checks on user-supplied URI parameters.

By specifying a malicious INBOX file in a request, the contents of the file may be disclosed to a remote attacker. All files would be accessed with the privileges of the user invoking Imp.

http://vulnerableserver/horde/imp/mailbox.php?mailbox=/etc/passwd