Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-1433

Опубликовано: 03 фев. 2015
Источник: ubuntu
Приоритет: medium
CVSS2: 4.3

Описание

program/lib/Roundcube/rcube_washtml.php in Roundcube before 1.0.5 does not properly quote strings, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the style attribute in an email.

РелизСтатусПримечание
artful

not-affected

0.9.5+dfsg1-4.2
bionic

not-affected

1.3.6+dfsg.1-1
cosmic

not-affected

1.3.6+dfsg.1-1
devel

not-affected

1.3.6+dfsg.1-1
disco

not-affected

1.3.6+dfsg.1-1
esm-apps/bionic

not-affected

1.3.6+dfsg.1-1
esm-apps/xenial

not-affected

0.9.5+dfsg1-4.2
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needed]
lucid

ignored

end of life
precise

ignored

end of life

Показывать по

4.3 Medium

CVSS2

Связанные уязвимости

nvd
около 11 лет назад

program/lib/Roundcube/rcube_washtml.php in Roundcube before 1.0.5 does not properly quote strings, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the style attribute in an email.

debian
около 11 лет назад

program/lib/Roundcube/rcube_washtml.php in Roundcube before 1.0.5 does ...

github
больше 3 лет назад

program/lib/Roundcube/rcube_washtml.php in Roundcube before 1.0.5 does not properly quote strings, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the style attribute in an email.

4.3 Medium

CVSS2