{"api_version":"1","generated_at":"2026-07-24T18:40:35+00:00","cve":"CVE-2001-1281","urls":{"html":"https://cve.report/CVE-2001-1281","api":"https://cve.report/api/cve/CVE-2001-1281.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2001-1281","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2001-1281"},"summary":{"title":"CVE-2001-1281","description":"Web Messaging Server for Ipswitch IMail 7.04 and earlier allows remote authenticated users to change information for other users by modifying the olduser parameter in the \"Change User Information\" web form.","state":"PUBLISHED","assigner":"mitre","published_at":"2001-10-12 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/3429","name":"http://www.securityfocus.com/bid/3429","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Ipswitch IMail Server User Modification Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://archives.neohapsis.com/archives/bugtraq/2001-10/0076.html","name":"http://archives.neohapsis.com/archives/bugtraq/2001-10/0076.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Neohapsis Archives - Bugtraq - Vulnerabilities in Ipswitch IMail Server 7.04 - From arne.vidstrom@ntsecurity.nu","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.ipswitch.com/Support/IMail/news.html","name":"http://www.ipswitch.com/Support/IMail/news.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"404 Page Not Found - Ipswitch","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2001-1281","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2001-1281","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2001","cve_id":"1281","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ipswitch","cpe5":"imail","cpe6":"6.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2001","cve_id":"1281","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ipswitch","cpe5":"imail","cpe6":"6.0.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2001","cve_id":"1281","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ipswitch","cpe5":"imail","cpe6":"7.0.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T04:51:07.651Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"3429","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/3429"},{"name":"20011011 Vulnerabilities in Ipswitch IMail Server 7.04","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2001-10/0076.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.ipswitch.com/Support/IMail/news.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2001-10-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"Web Messaging Server for Ipswitch IMail 7.04 and earlier allows remote authenticated users to change information for other users by modifying the olduser parameter in the \"Change User Information\" web form."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2002-05-09T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"3429","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/3429"},{"name":"20011011 Vulnerabilities in Ipswitch IMail Server 7.04","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://archives.neohapsis.com/archives/bugtraq/2001-10/0076.html"},{"tags":["x_refsource_MISC"],"url":"http://www.ipswitch.com/Support/IMail/news.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2001-1281","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Web Messaging Server for Ipswitch IMail 7.04 and earlier allows remote authenticated users to change information for other users by modifying the olduser parameter in the \"Change User Information\" web form."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"3429","refsource":"BID","url":"http://www.securityfocus.com/bid/3429"},{"name":"20011011 Vulnerabilities in Ipswitch IMail Server 7.04","refsource":"BUGTRAQ","url":"http://archives.neohapsis.com/archives/bugtraq/2001-10/0076.html"},{"name":"http://www.ipswitch.com/Support/IMail/news.html","refsource":"MISC","url":"http://www.ipswitch.com/Support/IMail/news.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2001-1281","datePublished":"2002-05-03T04:00:00.000Z","dateReserved":"2002-05-01T00:00:00.000Z","dateUpdated":"2024-08-08T04:51:07.651Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2001-10-12 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ipswitch:imail:6.0.2:*:*:*:*:*:*:*","matchCriteriaId":"56F7C097-B6D9-4C10-BDCD-245E5D387ADA"},{"vulnerable":true,"criteria":"cpe:2.3:a:ipswitch:imail:6.0.6:*:*:*:*:*:*:*","matchCriteriaId":"7B6613A7-3338-451F-876E-C544CCE2C066"},{"vulnerable":true,"criteria":"cpe:2.3:a:ipswitch:imail:7.0.4:*:*:*:*:*:*:*","matchCriteriaId":"84CE3C80-C0D3-4F7C-BF12-10111281DC3D"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2001","CveId":"1281","Ordinal":"1","Title":"CVE-2001-1281","CVE":"CVE-2001-1281","Year":"2001"},"notes":[{"CveYear":"2001","CveId":"1281","Ordinal":"1","NoteData":"Web Messaging Server for Ipswitch IMail 7.04 and earlier allows remote authenticated users to change information for other users by modifying the olduser parameter in the \"Change User Information\" web form.","Type":"Description","Title":"CVE-2001-1281"},{"CveYear":"2001","CveId":"1281","Ordinal":"2","NoteData":"2002-05-03","Type":"Other","Title":"Published"},{"CveYear":"2001","CveId":"1281","Ordinal":"3","NoteData":"2002-05-09","Type":"Other","Title":"Modified"}]}}}