CVE-2012-3507
CVE-2012-3507
Cross-site scripting (XSS) vulnerability in program/steps/mail/func.inc in RoundCube Webmail before 0.8.0, when using the Larry skin, allows remote attackers to inject arbitrary web script or HTML via the email message subject.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://secunia.com/advisories/50212http://sourceforge.net/projects/roundcubemail/files/roundcubemail/0.8.0/http://trac.roundcube.net/ticket/1488519http://www.openwall.com/lists/oss-security/2012/08/20/2http://www.openwall.com/lists/oss-security/2012/08/20/3http://www.openwall.com/lists/oss-security/2012/08/20/9http://www.securelist.com/en/advisories/50212