CVE-2013-1904

Absolute path traversal vulnerability in steps/mail/sendmail.inc in Roundcube Webmail before 0.7.3 and 0.8.x before 0.8.6 allows remote attackers...

Basic Information

CVE State
PUBLISHED
Reserved Date
February 19, 2013
Published Date
February 08, 2014
Last Updated
August 06, 2024
Vendor
Roundcube
Product
Webmail
Description
Absolute path traversal vulnerability in steps/mail/sendmail.inc in Roundcube Webmail before 0.7.3 and 0.8.x before 0.8.6 allows remote attackers to read arbitrary files via a full pathname in the _value parameter for the generic_message_footer setting in a save-perf action to index.php, as exploited in the wild in March 2013.
Tags
php

CVSS Scores

CVSS v2.0

5.0

Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Exploit Status

Exploited in the Wild
Yes (2014-02-08 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CVE 2014-02-08 00:00:00 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel