CVE-2002-2024 describes a path disclosure vulnerability in Horde IMP version 2.2.7. Remote attackers can exploit specific HTTP requests to trigger error messages that reveal the full web root pathname of the server. This vulnerability has a CVSS score of 5.3 (Medium), indicating it can be exploited remotely with low attack complexity, potentially leading to information disclosure. While the direct impact is limited to revealing server paths, this information could aid further reconnaissance. There is no known active exploitation, nor are there readily available exploit modules in Metasploit, Nuclei, or ExploitDB. Despite its age, the vulnerability has garnered significant community discussion, suggesting ongoing awareness or interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.2.7CPE matchmatch criteria | cpe:2.3:a:horde:imp:2.2.7:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.