Imp is a webmail system which uses the Horde framework.
Jouko Pynnonen reported that the Imp webmail version 2.x has a SQL
Imp can optionally store user preferences, contacts list and session
IDs in a SQL database. A remote attacker can use this vulnerability
to execute SQL commands and possibly get session IDs and steal
another user's webmail session. Other consequences are possible and
depend on the privileges Imp has in the database. Usually, these
privileges are limited to the Imp database itself, but this is site
and database specific.
This update also contains some fixes for Imp and Horde to make them
work with PHP 4.3.2.
It is recommended that all Imp users upgrade their packages.