4.3
CVSSv2

CVE-2007-6321

Published: 12/12/2007 Updated: 15/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in RoundCube webmail 0.1rc2, 2007-12-09, and previous versions versions, when using Internet Explorer, allows remote malicious users to inject arbitrary web script or HTML via style sheets containing expression commands.

Vulnerable Product Search on Vulmon Subscribe to Product

roundcube webmail

Vendor Advisories

Debian Bug report logs - #455840 CVE-2007-6321: Cross-site scripting (XSS) vulnerability Package: roundcube; Maintainer for roundcube is Debian Roundcube Maintainers <pkg-roundcube-maintainers@listsaliothdebianorg>; Source for roundcube is src:roundcube (PTS, buildd, popcon) Reported by: Micah Anderson <micah@debianor ...

Exploits

source: wwwsecurityfocuscom/bid/26800/info Roundcube Webmail is prone to an input-validation vulnerability because it fails to sanitize HTML email messages Attackers can exploit this issue to execute arbitrary script code in the browser of an unsuspecting user Successful attacks can allow attackers to steal cookie-based authentication ...