Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
roundcube webmail 0.2.1 vulnerabilities and exploits
(subscribe to this query)
10
CVSSv2
CVE-2008-5619
html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer prior to 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote malicious users to execute arbitrary code via crafted input that is processed by the ...
Roundcube Webmail 0.2.1
Roundcube Webmail 0.2.3
2 EDB exploits
7.5
CVSSv2
CVE-2013-6172
steps/utils/save_pref.inc in Roundcube webmail prior to 0.8.7 and 0.9.x prior to 0.9.5 allows remote malicious users to modify configuration settings via the _session parameter, which can be leveraged to read arbitrary files, conduct SQL injection attacks, and execute arbitrary c...
Roundcube Webmail 0.9
Roundcube Webmail 0.8.2
Roundcube Webmail 0.8.1
Roundcube Webmail 0.5.3
Roundcube Webmail 0.5.2
Roundcube Webmail 0.4
Roundcube Webmail 0.2.1
Roundcube Webmail 0.2
Roundcube Webmail 0.1
Roundcube Webmail 0.9.3
Roundcube Webmail 0.9.2
Roundcube Webmail
Roundcube Webmail 0.8.5
Roundcube Webmail 0.7.2
Roundcube Webmail 0.7.1
Roundcube Webmail 0.7
Roundcube Webmail 0.5
Roundcube Webmail 0.3
Roundcube Webmail 0.1.1
Roundcube Webmail 0.9.1
Roundcube Webmail 0.9.0
Roundcube Webmail 0.8.4
6.8
CVSSv2
CVE-2009-4076
Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and previous versions allows remote malicious users to hijack the authentication of unspecified users for requests that modify user information via unspecified vectors, a different vulnerability than CVE-2...
Roundcube Webmail 0.1
Roundcube Webmail 0.1.1
Roundcube Webmail 0.2
Roundcube Webmail 0.2.1
Roundcube Webmail
6.8
CVSSv2
CVE-2009-4077
Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and previous versions allows remote malicious users to hijack the authentication of unspecified users for requests that send arbitrary emails via unspecified vectors, a different vulnerability than CVE-200...
Roundcube Webmail 0.2.1
Roundcube Webmail 0.2
Roundcube Webmail 0.1
Roundcube Webmail 0.1.1
Roundcube Webmail
5.5
CVSSv2
CVE-2011-1492
steps/utils/modcss.inc in Roundcube Webmail prior to 0.5.1 does not properly verify that a request is an expected request for an external Cascading Style Sheets (CSS) stylesheet, which allows remote authenticated users to trigger arbitrary outbound TCP connections from the server...
Roundcube Webmail 0.1
Roundcube Webmail 0.3
Roundcube Webmail 0.4
Roundcube Webmail 0.1.1
Roundcube Webmail 0.2
Roundcube Webmail 0.4.2
Roundcube Webmail 0.5
Roundcube Webmail 0.2.1
Roundcube Webmail 0.4.1
Roundcube Webmail 0.3.1
Roundcube Webmail
5
CVSSv2
CVE-2013-1904
Absolute path traversal vulnerability in steps/mail/sendmail.inc in Roundcube Webmail prior to 0.7.3 and 0.8.x prior to 0.8.6 allows remote malicious users to read arbitrary files via a full pathname in the _value parameter for the generic_message_footer setting in a save-perf ac...
Roundcube Webmail 0.8.2
Roundcube Webmail 0.8.1
Roundcube Webmail 0.8.0
Roundcube Webmail
Roundcube Webmail 0.4
Roundcube Webmail 0.3.1
Roundcube Webmail 0.3
Roundcube Webmail 0.1
Roundcube Webmail 0.5.2
Roundcube Webmail 0.5.1
Roundcube Webmail 0.5
Roundcube Webmail 0.2
Roundcube Webmail 0.1.1
Roundcube Webmail 0.8.5
Roundcube Webmail 0.8.3
Roundcube Webmail 0.7.1
Roundcube Webmail 0.6
Roundcube Webmail 0.5.3
Roundcube Webmail 0.4.1
Roundcube Webmail 0.2.1
Roundcube Webmail 0.8.4
Roundcube Webmail 0.7
5
CVSSv2
CVE-2011-4078
include/iniset.php in Roundcube Webmail 0.5.4 and previous versions, when PHP 5.3.7 or 5.3.8 is used, allows remote malicious users to trigger a GET request for an arbitrary URL, and cause a denial of service (resource consumption and inbox outage), via a Subject header containin...
Roundcube Webmail 0.4.2
Roundcube Webmail 0.4
Roundcube Webmail 0.3
Roundcube Webmail 0.1
Roundcube Webmail 0.5.3
Roundcube Webmail
Roundcube Webmail 0.5.1
Roundcube Webmail 0.5
Roundcube Webmail 0.2
Roundcube Webmail 0.4.1
Roundcube Webmail 0.2.1
Roundcube Webmail 0.1.1
Roundcube Webmail 0.5.2
Roundcube Webmail 0.3.1
5
CVSSv2
CVE-2010-0464
Roundcube 0.3.1 and previous versions does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it easier for remote malicious users to determine the network location of the webmail user by logging DNS requests.
Roundcube Webmail 0.1
Roundcube Webmail 0.2.1
Roundcube Webmail 0.3
Roundcube Webmail 0.1.1
Roundcube Webmail 0.2
Roundcube Webmail
Roundcube Webmail 0.2.2
4.3
CVSSv2
CVE-2013-5645
Multiple cross-site scripting (XSS) vulnerabilities in Roundcube webmail prior to 0.9.3 allow user-assisted remote malicious users to inject arbitrary web script or HTML via the body of a message visited in (1) new or (2) draft mode, related to compose.inc; and (3) might allow re...
Roundcube Webmail 0.9
Roundcube Webmail 0.7.2
Roundcube Webmail 0.7.1
Roundcube Webmail 0.5
Roundcube Webmail 0.3
Roundcube Webmail 0.2
Roundcube Webmail 0.1.1
Roundcube Webmail 0.1
Roundcube Webmail 0.8.3
Roundcube Webmail 0.8.4
Roundcube Webmail 0.8.5
Roundcube Webmail
Roundcube Webmail 0.8.1
Roundcube Webmail 0.5.4
Roundcube Webmail 0.5.3
Roundcube Webmail 0.4
Roundcube Webmail 0.2.1
Roundcube Webmail 0.8.2
Roundcube Webmail 0.9.0
Roundcube Webmail 0.9.1
Roundcube Webmail 0.7
Roundcube Webmail 0.6
4.3
CVSSv2
CVE-2012-6121
Cross-site scripting (XSS) vulnerability in Roundcube Webmail prior to 0.8.5 allows remote malicious users to inject arbitrary web script or HTML via a (1) data:text or (2) vbscript link.
Roundcube Webmail 0.1
Roundcube Webmail 0.2
Roundcube Webmail 0.2.1
Roundcube Webmail 0.2.2
Roundcube Webmail 0.3
Roundcube Webmail 0.5.2
Roundcube Webmail 0.5.3
Roundcube Webmail 0.5.4
Roundcube Webmail 0.6
Roundcube Webmail 0.5
Roundcube Webmail 0.5.1
Roundcube Webmail 0.7
Roundcube Webmail 0.7.2
Roundcube Webmail 0.8.0
Roundcube Webmail 0.4
Roundcube Webmail 0.4.1
Roundcube Webmail 0.4.2
Roundcube Webmail 0.8.1
Roundcube Webmail 0.8.2
Roundcube Webmail 0.8.3
Roundcube Webmail
Roundcube Webmail 0.1.1
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4671
unauthorized
CVE-2024-4776
CVE-2024-3407
CVE-2024-26026
CVE-2024-32888
wireless
CVE-2024-4656
template injection
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »