356
VMScore

CVE-2015-5382

Published: 23/05/2017 Updated: 30/10/2018
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

program/steps/addressbook/photo.inc in Roundcube Webmail prior to 1.0.6 and 1.1.x prior to 1.1.2 allows remote authenticated users to read arbitrary files via the _alt parameter when uploading a vCard.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

roundcube roundcube webmail

roundcube roundcube webmail 1.1.1

roundcube webmail 1.1

Vendor Advisories

Debian Bug report logs - #791643 roundcube: CVE-2015-5381 CVE-2015-5382 CVE-2015-5383 Package: src:roundcube; Maintainer for src:roundcube is Debian Roundcube Maintainers <pkg-roundcube-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 7 Jul 2015 05:03:02 UTC Seve ...