<?xml version="1.0" encoding="UTF-8"?> 
<?xml-stylesheet href="https://dev.horde.org/themes/horde//default/feed-rss.xsl" type="text/xsl"?> 
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"> 
 <channel> 
  <title>Insecure: sensitive data in login screen</title> 
  <pubDate>Fri, 10 Apr 2026 09:35:34 +0000</pubDate> 
  <link>https://bugs.horde.org/ticket/1883</link> 
  <atom:link rel="self" type="application/rss+xml" title="Insecure: sensitive data in login screen" href="https://bugs.horde.org/ticket/1883/rss" /> 
  <description>Insecure: sensitive data in login screen</description> 
 
   
   
  <item> 
   <title>In &#039;imp/templates/login/login.inc&#039; there are several hidden </title> 
   <description>In &#039;imp/templates/login/login.inc&#039; there are several hidden form fields that expose potentially sensitive network information - including the private IP address of the mail server, TCP port number, mail protocol, and whether TLS is on or off. There&#039;s no need for this data to be sent to clients, other than for programmers&#039; convenience.



&lt;snip&gt;



        &lt;input type=&quot;hidden&quot; name=&quot;server&quot; value=&quot;10.100.0.23&quot; /&gt;

        &lt;input type=&quot;hidden&quot; name=&quot;port&quot; value=&quot;143&quot; /&gt;

        &lt;input type=&quot;hidden&quot; name=&quot;namespace&quot; value=&quot;INBOX.&quot; /&gt;

        &lt;input type=&quot;hidden&quot; name=&quot;maildomain&quot; value=&quot;enc.edu&quot; /&gt;

        &lt;input type=&quot;hidden&quot; name=&quot;protocol&quot; value=&quot;imap/notls&quot; /&gt;



&lt;/snip&gt;</description> 
   <pubDate>Thu, 28 Apr 2005 14:39:56 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/1883#t7780</link> 
  </item> 
   
  <item> 
   <title>Implemented in HEAD.  Since it touches some fairly critical </title> 
   <description>Implemented in HEAD.  Since it touches some fairly critical code, I want to run this for a week or two in head to make sure these changes are all good.</description> 
   <pubDate>Mon, 16 May 2005 05:03:00 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/1883#t8215</link> 
  </item> 
   
   
 
 </channel> 
</rss> 
