Show filters
202 Total Results
Displaying 71-80 of 202
Sort by:
Attacker Value
Unknown
CVE-2014-9587
Disclosure Date: January 15, 2015 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in Roundcube Webmail before 1.0.4 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, related to (1) address book operations or the (2) ACL or (3) Managesieve plugins.
0
Attacker Value
Unknown
CVE-2013-1904
Disclosure Date: February 08, 2014 (last updated October 05, 2023)
Absolute path traversal vulnerability in steps/mail/sendmail.inc in Roundcube Webmail before 0.7.3 and 0.8.x before 0.8.6 allows remote attackers to read arbitrary files via a full pathname in the _value parameter for the generic_message_footer setting in a save-perf action to index.php, as exploited in the wild in March 2013.
0
Attacker Value
Unknown
CVE-2013-6172
Disclosure Date: November 05, 2013 (last updated October 05, 2023)
steps/utils/save_pref.inc in Roundcube webmail before 0.8.7 and 0.9.x before 0.9.5 allows remote attackers to modify configuration settings via the _session parameter, which can be leveraged to read arbitrary files, conduct SQL injection attacks, and execute arbitrary code.
0
Attacker Value
Unknown
CVE-2013-5645
Disclosure Date: August 29, 2013 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Roundcube webmail before 0.9.3 allow user-assisted remote attackers to inject arbitrary web script or HTML via the body of a message visited in (1) new or (2) draft mode, related to compose.inc; and (3) might allow remote authenticated users to inject arbitrary web script or HTML via an HTML signature, related to save_identity.inc.
0
Attacker Value
Unknown
CVE-2013-5646
Disclosure Date: August 29, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Roundcube webmail 1.0-git allows remote authenticated users to inject arbitrary web script or HTML via the Name field of an addressbook group.
0
Attacker Value
Unknown
CVE-2012-6121
Disclosure Date: February 24, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.8.5 allows remote attackers to inject arbitrary web script or HTML via a (1) data:text or (2) vbscript link.
0
Attacker Value
Unknown
CVE-2012-5590
Disclosure Date: December 26, 2012 (last updated October 05, 2023)
SQL injection vulnerability in the Webmail Plus module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-5569
Disclosure Date: December 03, 2012 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allow remote attackers to inject arbitrary web script or HTML via a (1) page title or (2) crafted email message.
0
Attacker Value
Unknown
CVE-2012-4668
Disclosure Date: August 25, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Roundcube Webmail 0.8.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the signature in an email.
0
Attacker Value
Unknown
CVE-2012-3508
Disclosure Date: August 25, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in program/lib/washtml.php in Roundcube Webmail 0.8.0 allows remote attackers to inject arbitrary web script or HTML by using "javascript:" in an href attribute in the body of an HTML-formatted email.
0