5
CVSSv2

CVE-2013-1904

Published: 08/02/2014 Updated: 10/02/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Absolute path traversal vulnerability in steps/mail/sendmail.inc in Roundcube Webmail prior to 0.7.3 and 0.8.x prior to 0.8.6 allows remote malicious users to read arbitrary files via a full pathname in the _value parameter for the generic_message_footer setting in a save-perf action to index.php, as exploited in the wild in March 2013.

Vulnerable Product Search on Vulmon Subscribe to Product

roundcube webmail 0.8.2

roundcube webmail 0.8.1

roundcube webmail 0.8.0

roundcube webmail

roundcube webmail 0.4

roundcube webmail 0.3.1

roundcube webmail 0.3

roundcube webmail 0.1

roundcube webmail 0.5.2

roundcube webmail 0.5.1

roundcube webmail 0.5

roundcube webmail 0.2

roundcube webmail 0.1.1

roundcube webmail 0.8.5

roundcube webmail 0.8.3

roundcube webmail 0.7.1

roundcube webmail 0.6

roundcube webmail 0.5.3

roundcube webmail 0.4.1

roundcube webmail 0.2.1

roundcube webmail 0.8.4

roundcube webmail 0.7

roundcube webmail 0.5.4

roundcube webmail 0.4.2

roundcube webmail 0.2.2