CVE-2013-6172
Mandriva Linux Security Advisory 2013-263
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
steps/utils/save_pref.inc in Roundcube webmail before 0.8.7 and 0.9.x before 0.9.5 allows remote attackers to modify configuration settings via the _session parameter, which can be leveraged to read arbitrary files, conduct SQL injection attacks, and execute arbitrary code.
steps/utils/save_pref.inc en Roundcube webmail anterior a la versión 0.8.7 y 0.9.x anterior a 0.9.5 permite a atacantes remotos modificar las opciones de configuración a través del parámetro _session, que se puede aprovechar para leer archivos arbitrarios, llevar a cabo ataques de inyección SQL, y ejecutar código arbitrario.
It was discovered that roundcube does not properly sanitize the _session parameter in steps/utils/save_pref.inc during saving preferences. The vulnerability can be exploited to overwrite configuration settings and subsequently allowing random file access, manipulated SQL queries and even code execution. The updated packages have been patched to correct this issue.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-10-18 CVE Reserved
- 2013-10-28 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://www.interworx.com/developers/changelog/version-5-0-13-build-574-2014-02-19 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://roundcube.net/news/2013/10/21/security-updates-095-and-087 | 2014-03-26 | |
http://trac.roundcube.net/ticket/1489382 | 2014-03-26 |
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-updates/2014-03/msg00035.html | 2014-03-26 | |
http://www.debian.org/security/2013/dsa-2787 | 2014-03-26 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | <= 0.8.6 Search vendor "Roundcube" for product "Webmail" and version " <= 0.8.6" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.1 Search vendor "Roundcube" for product "Webmail" and version "0.1" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.1 Search vendor "Roundcube" for product "Webmail" and version "0.1" | 20050811 |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.1 Search vendor "Roundcube" for product "Webmail" and version "0.1" | 20050820 |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.1 Search vendor "Roundcube" for product "Webmail" and version "0.1" | 20051007 |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.1 Search vendor "Roundcube" for product "Webmail" and version "0.1" | 20051021 |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.1 Search vendor "Roundcube" for product "Webmail" and version "0.1" | alpha |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.1 Search vendor "Roundcube" for product "Webmail" and version "0.1" | beta |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.1 Search vendor "Roundcube" for product "Webmail" and version "0.1" | beta2 |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.1 Search vendor "Roundcube" for product "Webmail" and version "0.1" | rc1 |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.1 Search vendor "Roundcube" for product "Webmail" and version "0.1" | rc2 |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.1 Search vendor "Roundcube" for product "Webmail" and version "0.1" | stable |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.1.1 Search vendor "Roundcube" for product "Webmail" and version "0.1.1" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.2 Search vendor "Roundcube" for product "Webmail" and version "0.2" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.2 Search vendor "Roundcube" for product "Webmail" and version "0.2" | alpha |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.2 Search vendor "Roundcube" for product "Webmail" and version "0.2" | beta |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.2 Search vendor "Roundcube" for product "Webmail" and version "0.2" | stable |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.2.1 Search vendor "Roundcube" for product "Webmail" and version "0.2.1" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.2.2 Search vendor "Roundcube" for product "Webmail" and version "0.2.2" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.3 Search vendor "Roundcube" for product "Webmail" and version "0.3" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.3 Search vendor "Roundcube" for product "Webmail" and version "0.3" | beta |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.3 Search vendor "Roundcube" for product "Webmail" and version "0.3" | rc1 |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.3 Search vendor "Roundcube" for product "Webmail" and version "0.3" | stable |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.3.1 Search vendor "Roundcube" for product "Webmail" and version "0.3.1" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.4 Search vendor "Roundcube" for product "Webmail" and version "0.4" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.4 Search vendor "Roundcube" for product "Webmail" and version "0.4" | beta |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.4.1 Search vendor "Roundcube" for product "Webmail" and version "0.4.1" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.4.2 Search vendor "Roundcube" for product "Webmail" and version "0.4.2" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.5 Search vendor "Roundcube" for product "Webmail" and version "0.5" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.5 Search vendor "Roundcube" for product "Webmail" and version "0.5" | beta |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.5 Search vendor "Roundcube" for product "Webmail" and version "0.5" | rc |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.5.1 Search vendor "Roundcube" for product "Webmail" and version "0.5.1" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.5.2 Search vendor "Roundcube" for product "Webmail" and version "0.5.2" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.5.3 Search vendor "Roundcube" for product "Webmail" and version "0.5.3" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.5.4 Search vendor "Roundcube" for product "Webmail" and version "0.5.4" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.6 Search vendor "Roundcube" for product "Webmail" and version "0.6" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.7 Search vendor "Roundcube" for product "Webmail" and version "0.7" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.7.1 Search vendor "Roundcube" for product "Webmail" and version "0.7.1" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.7.2 Search vendor "Roundcube" for product "Webmail" and version "0.7.2" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.7.3 Search vendor "Roundcube" for product "Webmail" and version "0.7.3" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.8.0 Search vendor "Roundcube" for product "Webmail" and version "0.8.0" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.8.1 Search vendor "Roundcube" for product "Webmail" and version "0.8.1" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.8.2 Search vendor "Roundcube" for product "Webmail" and version "0.8.2" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.8.3 Search vendor "Roundcube" for product "Webmail" and version "0.8.3" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.8.4 Search vendor "Roundcube" for product "Webmail" and version "0.8.4" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.8.5 Search vendor "Roundcube" for product "Webmail" and version "0.8.5" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.9 Search vendor "Roundcube" for product "Webmail" and version "0.9" | beta |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.9 Search vendor "Roundcube" for product "Webmail" and version "0.9" | rc |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.9 Search vendor "Roundcube" for product "Webmail" and version "0.9" | rc2 |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.9.0 Search vendor "Roundcube" for product "Webmail" and version "0.9.0" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.9.1 Search vendor "Roundcube" for product "Webmail" and version "0.9.1" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.9.2 Search vendor "Roundcube" for product "Webmail" and version "0.9.2" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.9.3 Search vendor "Roundcube" for product "Webmail" and version "0.9.3" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.9.4 Search vendor "Roundcube" for product "Webmail" and version "0.9.4" | - |
Affected
|