Back

CVE-2002-0181

Cross-site scripting vulnerability in status.php3 for IMP 2.2.8 and HORDE 1.2.7 allows remote attackers to execute arbitrary web script and steal cookies of other IMP/HORDE users via the script parameter.

Published: Apr 22, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
horde horde 1.2.7
horde imp 2.2.8

GitHub Security Advisory GHSA-39q8-9vf4-gvf3

Cross-site scripting vulnerability in status.php3 for IMP 2.2.8 and HORDE 1.2.7 allows remote...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.85%

Top 23% most likely to be exploited

Threat Score 30.6 / 100

Data Sources

NVD EPSS GitHub