Show filters
202 Total Results
Displaying 71-80 of 202
Sort by:
Attacker Value
Unknown

CVE-2014-9587

Disclosure Date: January 15, 2015 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in Roundcube Webmail before 1.0.4 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, related to (1) address book operations or the (2) ACL or (3) Managesieve plugins.
0
Attacker Value
Unknown

CVE-2013-1904

Disclosure Date: February 08, 2014 (last updated October 05, 2023)
Absolute path traversal vulnerability in steps/mail/sendmail.inc in Roundcube Webmail before 0.7.3 and 0.8.x before 0.8.6 allows remote attackers to read arbitrary files via a full pathname in the _value parameter for the generic_message_footer setting in a save-perf action to index.php, as exploited in the wild in March 2013.
0
Attacker Value
Unknown

CVE-2013-6172

Disclosure Date: November 05, 2013 (last updated October 05, 2023)
steps/utils/save_pref.inc in Roundcube webmail before 0.8.7 and 0.9.x before 0.9.5 allows remote attackers to modify configuration settings via the _session parameter, which can be leveraged to read arbitrary files, conduct SQL injection attacks, and execute arbitrary code.
0
Attacker Value
Unknown

CVE-2013-5645

Disclosure Date: August 29, 2013 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Roundcube webmail before 0.9.3 allow user-assisted remote attackers to inject arbitrary web script or HTML via the body of a message visited in (1) new or (2) draft mode, related to compose.inc; and (3) might allow remote authenticated users to inject arbitrary web script or HTML via an HTML signature, related to save_identity.inc.
0
Attacker Value
Unknown

CVE-2013-5646

Disclosure Date: August 29, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Roundcube webmail 1.0-git allows remote authenticated users to inject arbitrary web script or HTML via the Name field of an addressbook group.
0
Attacker Value
Unknown

CVE-2012-6121

Disclosure Date: February 24, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.8.5 allows remote attackers to inject arbitrary web script or HTML via a (1) data:text or (2) vbscript link.
0
Attacker Value
Unknown

CVE-2012-5590

Disclosure Date: December 26, 2012 (last updated October 05, 2023)
SQL injection vulnerability in the Webmail Plus module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-5569

Disclosure Date: December 03, 2012 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allow remote attackers to inject arbitrary web script or HTML via a (1) page title or (2) crafted email message.
0
Attacker Value
Unknown

CVE-2012-4668

Disclosure Date: August 25, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Roundcube Webmail 0.8.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the signature in an email.
0
Attacker Value
Unknown

CVE-2012-3508

Disclosure Date: August 25, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in program/lib/washtml.php in Roundcube Webmail 0.8.0 allows remote attackers to inject arbitrary web script or HTML by using "javascript:" in an href attribute in the body of an HTML-formatted email.
0