CVE-2010-0464
https://notcve.org/view.php?id=CVE-2010-0464
Roundcube 0.3.1 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it easier for remote attackers to determine the network location of the webmail user by logging DNS requests. Roundcube v0.3.1 y anteriores no solicitan que el navegador web permita el "prefetching" DNS de los nombres de dominio contenidos en mensajes de correo electrónico, lo que facilita a atacantes remotos determinar la localización de red del usuario de webmail mediante peticiones de logggin DNS. • http://trac.roundcube.net/ticket/1486449 http://www.mandriva.com/security/advisories?name=MDVSA-2010:048 https://secure.grepular.com/DNS_Prefetch_Exposure_on_Thunderbird_and_Webmail • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2009-4077
https://notcve.org/view.php?id=CVE-2009-4077
Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote attackers to hijack the authentication of unspecified users for requests that send arbitrary emails via unspecified vectors, a different vulnerability than CVE-2009-4076. Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en Roundcube Webmail v0.2.2 y anteriores permite a atacantes remotos secuestrar la autenticación de usuarios sin especificar para peticiones que envían correos electrónicos arbitrarios a través de vectores sin especificar, una vulnerabilidad diferente a CVE-2009-4076. • http://jvn.jp/en/jp/JVN75694913/index.html http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000072.html http://secunia.com/advisories/37235 http://trac.roundcube.net/wiki/Changelog http://www.osvdb.org/59661 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2009-4076
https://notcve.org/view.php?id=CVE-2009-4076
Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote attackers to hijack the authentication of unspecified users for requests that modify user information via unspecified vectors, a different vulnerability than CVE-2009-4077. Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en Roundcube Webmail v0.2.2 y anteriores permite a atacantes remotos secuestrar la autenticación de usuarios sin especificar para peticiones que modifican la información del usuario a través de vectores inespecíficos, una vulnerabilidad diferente a CVE-2009-4077. • http://jvn.jp/en/jp/JVN72974205/index.html http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000071.html http://secunia.com/advisories/37235 http://trac.roundcube.net/wiki/Changelog http://www.osvdb.org/59661 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2009-0413
https://notcve.org/view.php?id=CVE-2009-0413
Cross-site scripting (XSS) vulnerability in RoundCube Webmail (roundcubemail) 0.2 stable allows remote attackers to inject arbitrary web script or HTML via the background attribute embedded in an HTML e-mail message. Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados en RoundCube Webmail (roundcubemail) v0.2 stable, permite a atacantes remotos inyectar secuencias de comandos web y HTML de su elección a través de un atributo oculto incrustado en un correo electrónico HTML. • http://secunia.com/advisories/33622 http://secunia.com/advisories/33827 http://trac.roundcube.net/changeset/2245 http://www.securityfocus.com/bid/33372 http://www.vupen.com/english/advisories/2009/0192 https://exchange.xforce.ibmcloud.com/vulnerabilities/48129 https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00082.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2008-5619 – Roundcube Webmail 0.2-3 Beta - Code Execution
https://notcve.org/view.php?id=CVE-2008-5619
html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote attackers to execute arbitrary code via crafted input that is processed by the preg_replace function with the eval switch. html2text.php en Chuggnutt HTML a Text Converter, como se usa en PHPMailer en versiones anteriores a 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha y 0.2-3.beta, Mahara y AtMail Open 1.03, permite a atacantes remotos ejecutar código arbitrario a través de entrada manipulada que se procesa por la función preg_replace con el interruptor de eval. RoundCube Webmail versions 0.2-3 Beta and below suffer from a remote code execution vulnerability. • https://www.exploit-db.com/exploits/7549 https://www.exploit-db.com/exploits/7553 http://mahara.org/interaction/forum/topic.php?id=533 http://osvdb.org/53893 http://secunia.com/advisories/33145 http://secunia.com/advisories/33170 http://secunia.com/advisories/34789 http://sourceforge.net/forum/forum.php?forum_id=898542 http://trac.roundcube.net/changeset/2148 http://trac.roundcube.net/ticket/1485618 http://www.openwall.com/lists/oss-security/2008/12/12/1 http: • CWE-94: Improper Control of Generation of Code ('Code Injection') •