Vulnerabilities
Vulnerable Software
Roundcube:  Security Vulnerabilities
html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote attackers to execute arbitrary code via crafted input that is processed by the preg_replace function with the eval switch.
CVSS Score
10.0
EPSS Score
0.777
Published
2008-12-17
RoundCube Webmail (roundcubemail) before 0.2-beta allows remote attackers to cause a denial of service (memory consumption) via crafted size parameters that are used to create a large quota image.
CVSS Score
7.8
EPSS Score
0.006
Published
2008-12-17
Cross-site scripting (XSS) vulnerability in RoundCube webmail 0.1rc2, 2007-12-09, and earlier versions, when using Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via style sheets containing expression commands.
CVSS Score
4.3
EPSS Score
0.076
Published
2007-12-12
roundcube webmail Alpha, with a default high verbose level ($rcmail_config['debug_level'] = 1), allows remote attackers to obtain the full path of the application via an invalid_task parameter, which leaks the path in an error message.
CVSS Score
5.0
EPSS Score
0.003
Published
2005-12-20


Contact Us

Shodan ® - All rights reserved