Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2015-5382

Disclosure Date: May 23, 2017 (last updated November 26, 2024)
program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via the _alt parameter when uploading a vCard.
0
Attacker Value
Unknown

CVE-2015-5383

Disclosure Date: May 23, 2017 (last updated November 26, 2024)
Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to obtain sensitive information by reading files in the (1) config, (2) temp, or (3) logs directory.
0
Attacker Value
Unknown

CVE-2015-5381

Disclosure Date: May 23, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter to the default URI.
0
Attacker Value
Unknown

CVE-2015-8864

Disclosure Date: April 13, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2016-4068.
0
Attacker Value
Unknown

CVE-2016-4068

Disclosure Date: April 13, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2015-8864.
0
Attacker Value
Unknown

CVE-2015-8770

Disclosure Date: January 29, 2016 (last updated November 25, 2024)
Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x before 1.1.4 allows remote authenticated users with certain permissions to read arbitrary files or possibly execute arbitrary code via a .. (dot dot) in the _skin parameter to index.php.
0
Attacker Value
Unknown

CVE-2015-8794

Disclosure Date: January 29, 2016 (last updated November 25, 2024)
Absolute path traversal vulnerability in program/steps/addressbook/photo.inc in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via a full pathname in the _alt parameter, related to contact photo handling.
0