Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-8770

Опубликовано: 29 янв. 2016
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 6
CVSS3: 7.5

Описание

Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x before 1.1.4 allows remote authenticated users with certain permissions to read arbitrary files or possibly execute arbitrary code via a .. (dot dot) in the _skin parameter to index.php.

РелизСтатусПримечание
artful

not-affected

1.1.4+dfsg.1-1
bionic

not-affected

1.3.6+dfsg.1-1
cosmic

not-affected

1.3.6+dfsg.1-1
devel

not-affected

1.3.6+dfsg.1-1
disco

not-affected

1.3.6+dfsg.1-1
esm-apps/bionic

not-affected

1.3.6+dfsg.1-1
esm-apps/xenial

not-affected

1.1.4+dfsg.1-1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needed]
precise

ignored

end of life
precise/esm

DNE

precise was needs-triage

Показывать по

EPSS

Процентиль: 96%
0.28303
Средний

6 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 10 лет назад

Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x before 1.1.4 allows remote authenticated users with certain permissions to read arbitrary files or possibly execute arbitrary code via a .. (dot dot) in the _skin parameter to index.php.

CVSS3: 7.5
debian
около 10 лет назад

Directory traversal vulnerability in the set_skin function in program/ ...

suse-cvrf
около 10 лет назад

Security update for roundcubemail

CVSS3: 7.5
github
больше 3 лет назад

Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x before 1.1.4 allows remote authenticated users with certain permissions to read arbitrary files or possibly execute arbitrary code via a .. (dot dot) in the _skin parameter to index.php.

EPSS

Процентиль: 96%
0.28303
Средний

6 Medium

CVSS2

7.5 High

CVSS3