Back

CVE-2001-1257

Cross-site scripting vulnerability in Horde Internet Messaging Program (IMP) before 2.2.6 and 1.2.6 allows remote attackers to execute arbitrary Javascript embedded in an email.

Published: Jul 21, 2001 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (7)

Vendor Product Version
horde imp 2.0
horde imp 2.2
horde imp 2.2.1
horde imp 2.2.2
horde imp 2.2.3
horde imp 2.2.4
horde imp 2.2.5

GitHub Security Advisory GHSA-3g85-rc94-jg7f

Cross-site scripting vulnerability in Horde Internet Messaging Program (IMP) before 2.2.6 and 1.2...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.97%

Top 22% most likely to be exploited

Threat Score 30.6 / 100

Data Sources

NVD EPSS GitHub