----------------------------------------------------------------------
A new version (0.9.0.0 - Release Candidate 1) of the free Secunia PSI
has been released. The new version includes many new and advanced
features, which makes it even easier to stay patched.
Download and test it today:
https://psi.secunia.com/
Read more about this new version:
https://psi.secunia.com/?page=changelog
----------------------------------------------------------------------
TITLE:
IMP Mail Deletion Security Bypass Vulnerability
SECUNIA ADVISORY ID:
SA28020
VERIFY ADVISORY:
http://secunia.com/advisories/28020/
CRITICAL:
Moderately critical
IMPACT:
Security Bypass, Cross Site Scripting, Manipulation of data
WHERE:
>From remote
SOFTWARE:
IMP Webmail Client 4.x
http://secunia.com/product/6376/
Horde Application Framework 3.x
http://secunia.com/product/4524/
Horde Groupware Webmail Edition 1.x
http://secunia.com/product/17151/
DESCRIPTION:
Secunia Research has discovered a vulnerability in IMP Webmail Client
and Horde Groupware Webmail Edition, which can be exploited by
malicious people to bypass certain security restrictions and
manipulate data.
The HTML filter does not filter out and