CVE-2011-2937
Mandriva Linux Security Advisory 2012-072
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in the UI messages functionality in Roundcube Webmail before 0.5.4 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter to the default URI.
Una vulnerabilidad de ejecución de comandos en sitios cruzados (XSS) en la funcionalidad de mensajes de interfaz de usuario en Roundcube Webmail antes de la versión v0.5.4 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro _mbox a la URI por defecto.
The login form in Roundcube Webmail before 0.5.1 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account and then compose an e-mail message, related to a login CSRF issue. Various other issues have also been addressed.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-07-27 CVE Reserved
- 2011-09-21 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://sourceforge.net/news/?group_id=139281&id=302769 | X_refsource_confirm | |
http://support.apple.com/kb/HT5130 | X_refsource_confirm |
|
http://trac.roundcube.net/browser/tags/roundcubemail/v0.5.4/CHANGELOG | X_refsource_confirm | |
http://www.openwall.com/lists/oss-security/2011/08/18/5 | Mailing List |
|
http://www.openwall.com/lists/oss-security/2011/08/19/15 | Mailing List |
|
http://www.securityfocus.com/bid/49229 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://trac.roundcube.net/ticket/1488030 | 2024-08-06 | |
https://bugzilla.redhat.com/show_bug.cgi?id=731786 | 2024-08-06 |
URL | Date | SRC |
---|---|---|
http://trac.roundcube.net/changeset/5037 | 2012-02-04 |
URL | Date | SRC |
---|---|---|
http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html | 2012-02-04 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | <= 0.5.3 Search vendor "Roundcube" for product "Webmail" and version " <= 0.5.3" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.1 Search vendor "Roundcube" for product "Webmail" and version "0.1" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.1 Search vendor "Roundcube" for product "Webmail" and version "0.1" | alpha |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.1 Search vendor "Roundcube" for product "Webmail" and version "0.1" | beta |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.1 Search vendor "Roundcube" for product "Webmail" and version "0.1" | beta2 |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.1 Search vendor "Roundcube" for product "Webmail" and version "0.1" | rc1 |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.1 Search vendor "Roundcube" for product "Webmail" and version "0.1" | rc2 |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.1.1 Search vendor "Roundcube" for product "Webmail" and version "0.1.1" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.2 Search vendor "Roundcube" for product "Webmail" and version "0.2" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.2 Search vendor "Roundcube" for product "Webmail" and version "0.2" | alpha |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.2 Search vendor "Roundcube" for product "Webmail" and version "0.2" | beta |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.2.1 Search vendor "Roundcube" for product "Webmail" and version "0.2.1" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.3 Search vendor "Roundcube" for product "Webmail" and version "0.3" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.3 Search vendor "Roundcube" for product "Webmail" and version "0.3" | beta |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.3 Search vendor "Roundcube" for product "Webmail" and version "0.3" | rc1 |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.3.1 Search vendor "Roundcube" for product "Webmail" and version "0.3.1" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.4 Search vendor "Roundcube" for product "Webmail" and version "0.4" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.4 Search vendor "Roundcube" for product "Webmail" and version "0.4" | beta |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.4.1 Search vendor "Roundcube" for product "Webmail" and version "0.4.1" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.4.2 Search vendor "Roundcube" for product "Webmail" and version "0.4.2" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.5 Search vendor "Roundcube" for product "Webmail" and version "0.5" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.5 Search vendor "Roundcube" for product "Webmail" and version "0.5" | beta |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.5 Search vendor "Roundcube" for product "Webmail" and version "0.5" | rc |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.5.1 Search vendor "Roundcube" for product "Webmail" and version "0.5.1" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.5.2 Search vendor "Roundcube" for product "Webmail" and version "0.5.2" | - |
Affected
|