Show filters
68 Total Results
Displaying 41-50 of 68
Sort by:
Attacker Value
Unknown
CVE-2016-4069
Disclosure Date: August 25, 2016 (last updated November 25, 2024)
Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail before 1.1.5 allows remote attackers to hijack the authentication of users for requests that download attachments and cause a denial of service (disk consumption) via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-8770
Disclosure Date: January 29, 2016 (last updated November 25, 2024)
Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x before 1.1.4 allows remote authenticated users with certain permissions to read arbitrary files or possibly execute arbitrary code via a .. (dot dot) in the _skin parameter to index.php.
0
Attacker Value
Unknown
CVE-2015-8793
Disclosure Date: January 29, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter in a mail task to the default URL, a different vulnerability than CVE-2011-2937.
0
Attacker Value
Unknown
CVE-2015-8794
Disclosure Date: January 29, 2016 (last updated November 25, 2024)
Absolute path traversal vulnerability in program/steps/addressbook/photo.inc in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via a full pathname in the _alt parameter, related to contact photo handling.
0
Attacker Value
Unknown
CVE-2015-8105
Disclosure Date: November 10, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in program/js/app.js in Roundcube webmail before 1.0.7 and 1.1.x before 1.1.3 allows remote authenticated users to inject arbitrary web script or HTML via the file name in a drag-n-drop file upload.
0
Attacker Value
Unknown
CVE-2015-1433
Disclosure Date: February 03, 2015 (last updated October 05, 2023)
program/lib/Roundcube/rcube_washtml.php in Roundcube before 1.0.5 does not properly quote strings, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the style attribute in an email.
0
Attacker Value
Unknown
CVE-2014-9587
Disclosure Date: January 15, 2015 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in Roundcube Webmail before 1.0.4 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, related to (1) address book operations or the (2) ACL or (3) Managesieve plugins.
0
Attacker Value
Unknown
CVE-2013-1904
Disclosure Date: February 08, 2014 (last updated October 05, 2023)
Absolute path traversal vulnerability in steps/mail/sendmail.inc in Roundcube Webmail before 0.7.3 and 0.8.x before 0.8.6 allows remote attackers to read arbitrary files via a full pathname in the _value parameter for the generic_message_footer setting in a save-perf action to index.php, as exploited in the wild in March 2013.
0
Attacker Value
Unknown
CVE-2013-6172
Disclosure Date: November 05, 2013 (last updated October 05, 2023)
steps/utils/save_pref.inc in Roundcube webmail before 0.8.7 and 0.9.x before 0.9.5 allows remote attackers to modify configuration settings via the _session parameter, which can be leveraged to read arbitrary files, conduct SQL injection attacks, and execute arbitrary code.
0
Attacker Value
Unknown
CVE-2013-5645
Disclosure Date: August 29, 2013 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Roundcube webmail before 0.9.3 allow user-assisted remote attackers to inject arbitrary web script or HTML via the body of a message visited in (1) new or (2) draft mode, related to compose.inc; and (3) might allow remote authenticated users to inject arbitrary web script or HTML via an HTML signature, related to save_identity.inc.
0