2.6
CVSSv2

CVE-2012-3507

Published: 25/08/2012 Updated: 24/08/2015
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in program/steps/mail/func.inc in RoundCube Webmail prior to 0.8.0, when using the Larry skin, allows remote malicious users to inject arbitrary web script or HTML via the email message subject.

Vulnerable Product Search on Vulmon Subscribe to Product

roundcube webmail 0.1

roundcube webmail 0.2.2

roundcube webmail 0.3

roundcube webmail 0.4

roundcube webmail 0.4.2

roundcube webmail 0.5.4

roundcube webmail 0.7

roundcube webmail 0.3.1

roundcube webmail 0.7.2

roundcube webmail

roundcube webmail 0.1.1

roundcube webmail 0.2

roundcube webmail 0.5

roundcube webmail 0.5.1

roundcube webmail 0.5.2

roundcube webmail 0.2.1

roundcube webmail 0.4.1

roundcube webmail 0.5.3

roundcube webmail 0.6

roundcube webmail 0.7.1