Описание
Cross-site scripting (XSS) vulnerability in program/steps/mail/func.inc in RoundCube Webmail before 0.8.0, when using the Larry skin, allows remote attackers to inject arbitrary web script or HTML via the email message subject.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 0.8rc only |
| hardy | not-affected | 0.8rc only |
| lucid | not-affected | 0.8rc only |
| natty | not-affected | 0.8rc only |
| oneiric | not-affected | 0.8rc only |
| precise | not-affected | 0.8rc only |
| upstream | needs-triage |
Показывать по
2.6 Low
CVSS2
Связанные уязвимости
Cross-site scripting (XSS) vulnerability in program/steps/mail/func.inc in RoundCube Webmail before 0.8.0, when using the Larry skin, allows remote attackers to inject arbitrary web script or HTML via the email message subject.
Cross-site scripting (XSS) vulnerability in program/steps/mail/func.in ...
Cross-site scripting (XSS) vulnerability in program/steps/mail/func.inc in RoundCube Webmail before 0.8.0, when using the Larry skin, allows remote attackers to inject arbitrary web script or HTML via the email message subject.
2.6 Low
CVSS2