Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown

CVE-2015-5382

Disclosure Date: May 23, 2017 (last updated November 26, 2024)
program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via the _alt parameter when uploading a vCard.
0
Attacker Value
Unknown

CVE-2015-5383

Disclosure Date: May 23, 2017 (last updated November 26, 2024)
Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to obtain sensitive information by reading files in the (1) config, (2) temp, or (3) logs directory.
0
Attacker Value
Unknown

CVE-2015-5381

Disclosure Date: May 23, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter to the default URI.
0
Attacker Value
Unknown

CVE-2015-8864

Disclosure Date: April 13, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2016-4068.
0
Attacker Value
Unknown

CVE-2016-4068

Disclosure Date: April 13, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2015-8864.
0
Attacker Value
Unknown

CVE-2015-8770

Disclosure Date: January 29, 2016 (last updated November 25, 2024)
Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x before 1.1.4 allows remote authenticated users with certain permissions to read arbitrary files or possibly execute arbitrary code via a .. (dot dot) in the _skin parameter to index.php.
0
Attacker Value
Unknown

CVE-2015-8793

Disclosure Date: January 29, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter in a mail task to the default URL, a different vulnerability than CVE-2011-2937.
0
Attacker Value
Unknown

CVE-2015-8794

Disclosure Date: January 29, 2016 (last updated November 25, 2024)
Absolute path traversal vulnerability in program/steps/addressbook/photo.inc in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via a full pathname in the _alt parameter, related to contact photo handling.
0
Attacker Value
Unknown

CVE-2015-8105

Disclosure Date: November 10, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in program/js/app.js in Roundcube webmail before 1.0.7 and 1.1.x before 1.1.3 allows remote authenticated users to inject arbitrary web script or HTML via the file name in a drag-n-drop file upload.
0
Attacker Value
Unknown

CVE-2012-0909

Disclosure Date: January 24, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Horde_Form in Horde Groupware Webmail Edition before 4.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to email verification. NOTE: Some of these details are obtained from third party information.
0