Vulnerabilities
Vulnerable Software
Roundcube:  >> Webmail  >> 0.5.4  Security Vulnerabilities
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.7, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via vectors involving an embedded image attachment.
CVSS Score
2.6
EPSS Score
0.003
Published
2012-06-04
include/iniset.php in Roundcube Webmail 0.5.4 and earlier, when PHP 5.3.7 or 5.3.8 is used, allows remote attackers to trigger a GET request for an arbitrary URL, and cause a denial of service (resource consumption and inbox outage), via a Subject header containing only a URL, a related issue to CVE-2011-3379.
CVSS Score
5.0
EPSS Score
0.009
Published
2011-11-03


Contact Us

Shodan ® - All rights reserved