Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-8794

Опубликовано: 29 янв. 2016
Источник: debian

Описание

Absolute path traversal vulnerability in program/steps/addressbook/photo.inc in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via a full pathname in the _alt parameter, related to contact photo handling.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
roundcubefixed1.1.2+dfsg.1-1package
roundcubenot-affectedwheezypackage
roundcubenot-affectedsqueezepackage

Примечания

  • http://www.scip.ch/en/?vuldb.80732

  • http://web.archive.org/web/20160329044745/http://roundcube.net/news/2015/06/05/updates-1.1.2-and-1.0.6-released

  • http://trac.roundcube.net/ticket/1490379

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 10 лет назад

Absolute path traversal vulnerability in program/steps/addressbook/photo.inc in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via a full pathname in the _alt parameter, related to contact photo handling.

CVSS3: 6.5
nvd
около 10 лет назад

Absolute path traversal vulnerability in program/steps/addressbook/photo.inc in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via a full pathname in the _alt parameter, related to contact photo handling.

CVSS3: 6.5
github
больше 3 лет назад

Absolute path traversal vulnerability in program/steps/addressbook/photo.inc in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via a full pathname in the _alt parameter, related to contact photo handling.