Show filters
202 Total Results
Displaying 51-60 of 202
Sort by:
Attacker Value
Unknown

CVE-2017-16651

Disclosure Date: November 09, 2017 (last updated November 26, 2024)
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests.
Attacker Value
Unknown

CVE-2017-14597

Disclosure Date: September 19, 2017 (last updated November 26, 2024)
AdminPanel in AfterLogic WebMail 7.7 and Aurora 7.7.5 has XSS via the txtDomainName field to adminpanel/modules/pro/inc/ajax.php during addition of a domain.
0
Attacker Value
Unknown

CVE-2015-5382

Disclosure Date: May 23, 2017 (last updated November 26, 2024)
program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via the _alt parameter when uploading a vCard.
0
Attacker Value
Unknown

CVE-2015-5383

Disclosure Date: May 23, 2017 (last updated November 26, 2024)
Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to obtain sensitive information by reading files in the (1) config, (2) temp, or (3) logs directory.
0
Attacker Value
Unknown

CVE-2015-5381

Disclosure Date: May 23, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter to the default URI.
0
Attacker Value
Unknown

CVE-2017-8114

Disclosure Date: April 29, 2017 (last updated November 26, 2024)
Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin.
Attacker Value
Unknown

CVE-2015-8864

Disclosure Date: April 13, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2016-4068.
0
Attacker Value
Unknown

CVE-2016-4068

Disclosure Date: April 13, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2015-8864.
0
Attacker Value
Unknown

CVE-2017-6820

Disclosure Date: March 12, 2017 (last updated November 26, 2024)
rcube_utils.php in Roundcube before 1.1.8 and 1.2.x before 1.2.4 is susceptible to a cross-site scripting vulnerability via a crafted Cascading Style Sheets (CSS) token sequence within an SVG element.
0
Attacker Value
Unknown

CVE-2015-2180

Disclosure Date: January 30, 2017 (last updated November 25, 2024)
The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the password.
0