Описание
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
Ссылки
- Mailing ListThird Party Advisory
- ExploitThird Party Advisory
- Patch
- Release Notes
- Release Notes
- Release NotesVendor Advisory
- Third Party Advisory
- Mailing ListThird Party Advisory
- ExploitThird Party Advisory
- Patch
- Release Notes
- Release Notes
- Release NotesVendor Advisory
- Third Party Advisory
- US Government Resource
Уязвимые конфигурации
Одно из
Одно из
EPSS
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
Связанные уязвимости
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to ...
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
Уязвимость функций im_convert_path и im_identify_path файла rcube_image.php почтового клиента RoundCube Webmail, позволяющая нарушителю выполнить произвольный код
EPSS
9.8 Critical
CVSS3
7.5 High
CVSS2