[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2787-1 roundcube -- design error

ID: oval:org.secpod.oval:def:601136Date: (C)2013-10-28   (M)2022-10-10
Class: PATCHFamily: unix




It was discovered that roundcube, a skinnable AJAX based webmail solution for IMAP servers, does not properly sanitize the _session parameter in steps/utils/save_pref.inc during saving preferences. The vulnerability can be exploited to overwrite configuration settings and subsequently allowing random file access, manipulated SQL queries and even code execution. roundcube in the oldstable distribution is not affected by this problem.

Platform:
Debian 7.0
Product:
roundcube
Reference:
DSA-2787-1
CVE-2013-6172
CVE    1
CVE-2013-6172
CPE    2
cpe:/a:roundcube:roundcube
cpe:/o:debian:debian_linux:7.0

© SecPod Technologies