3 results (0.007 seconds)

CVSS: 6.5EPSS: 0%CPEs: 5EXPL: 0

program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via the _alt parameter when uploading a vCard. program/steps/addressbook/photo.inc en Roundcube Webmail, en versiones anteriores a la 1.0.6 y 1.1.x anteriores a la 1.1.2, permitiría a usuarios remotos autenticados leer ficheros arbitrarios a través del parámetro _alt parameter cuando cargamos una vCard. • http://www.openwall.com/lists/oss-security/2015/07/07/2 http://www.openwall.com/lists/oss-security/2015/07/07/3 https://github.com/roundcube/roundcubemail/commit/6ccd4c54bcc4cb77365defabe8bbe7d10b2620d4 https://github.com/roundcube/roundcubemail/commit/e84fafcec22e7b460db03248dc23ed6b053b15c9 https://github.com/roundcube/roundcubemail/issues/4817 https://roundcube.net/news/2015/06/05/updates-1.1.2-and-1.0.6-released • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 6.5EPSS: 0%CPEs: 3EXPL: 0

Absolute path traversal vulnerability in program/steps/addressbook/photo.inc in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via a full pathname in the _alt parameter, related to contact photo handling. Vulnerabilidad de salto de ruta absoluta en program/steps/addressbook/photo.inc en Roundcube en versiones anteriores a 1.0.6 y 1.1.x en versiones anteriores a 1.1.2 permite a usuarios remotos autenticados leer archivos arbitrarios a través de un nombre de ruta completa en el parámetro _alt, relacionado con la manipulación de la foto de contacto. • http://trac.roundcube.net/changeset/6ccd4c54b/github http://trac.roundcube.net/changeset/e84fafcec/github http://trac.roundcube.net/ticket/1490379 https://roundcube.net/news/2015/06/05/updates-1.1.2-and-1.0.6-released • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 7.5EPSS: 11%CPEs: 5EXPL: 3

Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x before 1.1.4 allows remote authenticated users with certain permissions to read arbitrary files or possibly execute arbitrary code via a .. (dot dot) in the _skin parameter to index.php. Vulnerabilidad de salto de directorio en la función set_skin en program/include/rcmail_output_html.php en Roundcube en versiones anteriores a 1.0.8 y 1.1.x en versiones anteriores a 1.1.4 permite a usuarios remotos autenticados con ciertos permisos leer archivos arbitrarios o posiblemente ejecutar código arbitrario a través de un .. (punto punto) en el parámetro _skin en index.php. Roundcube version 1.1.3 suffers from a path traversal vulnerability. • https://www.exploit-db.com/exploits/39245 http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00028.html http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00029.html http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00030.html http://packetstormsecurity.com/files/135274/Roundcube-1.1.3-Path-Traversal.html http://trac.roundcube.net/changeset/10e5192a2b/github http://trac.roundcube.net/ticket/1490620 http://www.debian.org/security/2016/dsa-3541 http:/ • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •