605
VMScore

CVE-2015-8770

Published: 29/01/2016 Updated: 09/10/2018
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
CVSS v3 Base Score: 7.5 | Impact Score: 5.9 | Exploitability Score: 1.6
VMScore: 605
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube prior to 1.0.8 and 1.1.x prior to 1.1.4 allows remote authenticated users with certain permissions to read arbitrary files or possibly execute arbitrary code via a .. (dot dot) in the _skin parameter to index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

roundcube roundcube webmail 1.1.2

roundcube roundcube webmail 1.1.1

roundcube roundcube webmail 1.1.0

roundcube roundcube webmail

roundcube roundcube webmail 1.1.3

Exploits

Advisory ID: HTB23283 Product: Roundcube Vendor: Roundcubenet Vulnerable Version(s): 113 and probably prior Tested Version: 113 Advisory Publication: December 21, 2015 [without technical details] Vendor Notification: December 21, 2015 Vendor Patch: December 26, 2015 Public Disclosure: January 13, 2016 Vulnerability Type: Path Traversal [C ...
Roundcube version 113 suffers from a path traversal vulnerability ...