Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2011-1491
Description:The login form in Roundcube Webmail before 0.5.1 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account and then compose an e-mail message, related to a "login CSRF" issue.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2011-1491
[oss-security] 20110324 CVE request: roundcube < 0.5.1 CSRF
http://openwall.com/lists/oss-security/2011/03/24/3
[oss-security] 20110324 Re: CVE request: roundcube < 0.5.1 CSRF
http://openwall.com/lists/oss-security/2011/03/24/4
[oss-security] 20110404 Re: CVE request: roundcube < 0.5.1 CSRF
http://openwall.com/lists/oss-security/2011/04/04/50
http://trac.roundcube.net/changeset/4490
http://trac.roundcube.net/changeset/4490
http://trac.roundcube.net/wiki/Changelog
http://trac.roundcube.net/wiki/Changelog
roundcube-login-info-disclosure(66815)
https://exchange.xforce.ibmcloud.com/vulnerabilities/66815




© 1998-2025 E-Soft Inc. All rights reserved.