Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2017-16651
Description:Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests.
Test IDs: 1.3.6.1.4.1.25623.1.0.873703   1.3.6.1.4.1.25623.1.1.1.2.2017.1193   1.3.6.1.4.1.25623.1.1.10.2017.0409   1.3.6.1.4.1.25623.1.0.112134   1.3.6.1.4.1.25623.1.0.704030   1.3.6.1.4.1.25623.1.0.873709   1.3.6.1.4.1.25623.1.1.12.2025.7200.1  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2017-16651
BugTraq ID: 101793
http://www.securityfocus.com/bid/101793
Debian Security Information: DSA-4030 (Google Search)
https://www.debian.org/security/2017/dsa-4030
http://packetstormsecurity.com/files/161226/Roundcube-Webmail-1.2-File-Disclosure.html
https://lists.debian.org/debian-lts-announce/2017/11/msg00039.html




© 1998-2025 E-Soft Inc. All rights reserved.