Vulnerabilities
Vulnerable Software
Roundcube:  >> Webmail  >> 0.2.2  Security Vulnerabilities
steps/utils/modcss.inc in Roundcube Webmail before 0.5.1 does not properly verify that a request is an expected request for an external Cascading Style Sheets (CSS) stylesheet, which allows remote authenticated users to trigger arbitrary outbound TCP connections from the server, and possibly obtain sensitive information, via a crafted request.
CVSS Score
5.5
EPSS Score
0.004
Published
2011-04-08
Roundcube 0.3.1 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it easier for remote attackers to determine the network location of the webmail user by logging DNS requests.
CVSS Score
5.0
EPSS Score
0.003
Published
2010-01-29
Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote attackers to hijack the authentication of unspecified users for requests that modify user information via unspecified vectors, a different vulnerability than CVE-2009-4077.
CVSS Score
6.8
EPSS Score
0.002
Published
2009-11-25
Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote attackers to hijack the authentication of unspecified users for requests that send arbitrary emails via unspecified vectors, a different vulnerability than CVE-2009-4076.
CVSS Score
6.8
EPSS Score
0.002
Published
2009-11-25


Contact Us

Shodan ® - All rights reserved