← Vulnerability feed

Vulnerability record · CVE-2007-6018 · published 11 January 2008

CVE-2007-6018: Horde framework permissions and access controls vulnerability

Horde · Framework

IMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3 does not validate unspecified HTTP requests, which allows remote attackers to (1) delete arbitrary e-mail messages via a modified numeric ID or (2) "purge" deleted emails via a crafted email message.

5.8 CVSS 2.0 Medium EPSS 1.8% · top 22.7% CWE-264 · Permissions and access controls
5.8CVSS 2.0 base score
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
38References
16 Jun 2026Last modified by NVD

Description

IMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3 does not validate unspecified HTTP requests, which allows remote attackers to (1) delete arbitrary e-mail messages via a modified numeric ID or (2) "purge" deleted emails via a crafted email message.

AV:N/AC:M/Au:N/C:P/I:P/A:N

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://cvs.horde.org/diff.php/groupware/docs/groupware/CHANGES?r1=1.17&r2=1.17.2.1&ty=h
http://cvs.horde.org/diff.php/groupware/docs/webmail/CHANGES?r1=1.12&r2=1.12.2.1&ty=h
http://lists.horde.org/archives/announce/2008/000360.html
http://lists.horde.org/archives/announce/2008/000365.html
http://lists.horde.org/archives/announce/2008/000366.html
http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html
http://secunia.com/advisories/28020 Vendor Advisory
http://secunia.com/advisories/28546
http://secunia.com/advisories/29184
http://secunia.com/advisories/29185
http://secunia.com/advisories/29186
http://secunia.com/advisories/34418
http://secunia.com/secunia_research/2007-102/advisory/ Vendor Advisory
http://www.debian.org/security/2008/dsa-1470
http://www.securityfocus.com/bid/27223 Patch
https://bugzilla.redhat.com/show_bug.cgi?id=428625
https://exchange.xforce.ibmcloud.com/vulnerabilities/39595
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00888.html
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00927.html
http://cvs.horde.org/diff.php/groupware/docs/groupware/CHANGES?r1=1.17&r2=1.17.2.1&ty=h
http://cvs.horde.org/diff.php/groupware/docs/webmail/CHANGES?r1=1.12&r2=1.12.2.1&ty=h
http://lists.horde.org/archives/announce/2008/000360.html
http://lists.horde.org/archives/announce/2008/000365.html
http://lists.horde.org/archives/announce/2008/000366.html
http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html
http://secunia.com/advisories/28020 Vendor Advisory
http://secunia.com/advisories/28546
http://secunia.com/advisories/29184
http://secunia.com/advisories/29185
http://secunia.com/advisories/29186
http://secunia.com/advisories/34418
http://secunia.com/secunia_research/2007-102/advisory/ Vendor Advisory
http://www.debian.org/security/2008/dsa-1470
http://www.securityfocus.com/bid/27223 Patch
https://bugzilla.redhat.com/show_bug.cgi?id=428625
https://exchange.xforce.ibmcloud.com/vulnerabilities/39595
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00888.html
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00927.html

Track CVE-2007-6018 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-7218Horde groupware vulnerabilityUnspecified vulnerability in the Horde API in Horde 3.1 before 3.1.6 and 3.2 before 3.2 before 3.2-RC2; Turba H3 2.1 before 2.1.6 and 2.2 before 2.2-…EPSS 2.2%10.0CVE-2008-7219Horde groupware permissions and access controls vulnerabilityHorde Kronolith H3 2.1 before 2.1.7 and 2.2 before 2.2-RC2; Nag H3 2.1 before 2.1.4 and 2.2 before 2.2-RC2; Mnemo H3 2.1 before 2.1.2 and H3 2.2 befo…EPSS 2.7%10.0CVE-2005-3344Horde vulnerabilityThe default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain access.EPSS 8.0%9.0CVE-2008-3650Horde groupware webmail edition vulnerabilityMultiple unspecified vulnerabilities in Horde Groupware Webmail before Edition 1.1.1 (final) have unknown impact and attack vectors related to "unesc…EPSS 1.0%7.5CVE-2012-0209Horde open_calendar.js trojan enables remote PHP code executionHorde 3.3.12, Horde Groupware 1.2.10 and Groupware Webmail Edition 1.2.10 distributed via FTP between November 2011 and February 2012 contained an ex…EPSS 72%analysed7.5CVE-2003-0025Horde imp vulnerabilityMultiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possibly gain …EPSS 28%7.5CVE-2002-0181Horde vulnerabilityCross-site scripting vulnerability in status.php3 for IMP 2.2.8 and HORDE 1.2.7 allows remote attackers to execute arbitrary web script and steal coo…EPSS 1.8%7.5CVE-2001-1257Horde imp vulnerabilityCross-site scripting vulnerability in Horde Internet Messaging Program (IMP) before 2.2.6 and 1.2.6 allows remote attackers to execute arbitrary Java…EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2007-6018), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.