Логотип exploitDog
bind:CVE-2011-1492
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2011-1492

Количество 4

Количество 4

ubuntu логотип

CVE-2011-1492

больше 14 лет назад

steps/utils/modcss.inc in Roundcube Webmail before 0.5.1 does not properly verify that a request is an expected request for an external Cascading Style Sheets (CSS) stylesheet, which allows remote authenticated users to trigger arbitrary outbound TCP connections from the server, and possibly obtain sensitive information, via a crafted request.

CVSS2: 5.5
EPSS: Низкий
nvd логотип

CVE-2011-1492

больше 14 лет назад

steps/utils/modcss.inc in Roundcube Webmail before 0.5.1 does not properly verify that a request is an expected request for an external Cascading Style Sheets (CSS) stylesheet, which allows remote authenticated users to trigger arbitrary outbound TCP connections from the server, and possibly obtain sensitive information, via a crafted request.

CVSS2: 5.5
EPSS: Низкий
debian логотип

CVE-2011-1492

больше 14 лет назад

steps/utils/modcss.inc in Roundcube Webmail before 0.5.1 does not prop ...

CVSS2: 5.5
EPSS: Низкий
github логотип

GHSA-r646-w9ph-62w9

больше 3 лет назад

steps/utils/modcss.inc in Roundcube Webmail before 0.5.1 does not properly verify that a request is an expected request for an external Cascading Style Sheets (CSS) stylesheet, which allows remote authenticated users to trigger arbitrary outbound TCP connections from the server, and possibly obtain sensitive information, via a crafted request.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2011-1492

steps/utils/modcss.inc in Roundcube Webmail before 0.5.1 does not properly verify that a request is an expected request for an external Cascading Style Sheets (CSS) stylesheet, which allows remote authenticated users to trigger arbitrary outbound TCP connections from the server, and possibly obtain sensitive information, via a crafted request.

CVSS2: 5.5
0%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-1492

steps/utils/modcss.inc in Roundcube Webmail before 0.5.1 does not properly verify that a request is an expected request for an external Cascading Style Sheets (CSS) stylesheet, which allows remote authenticated users to trigger arbitrary outbound TCP connections from the server, and possibly obtain sensitive information, via a crafted request.

CVSS2: 5.5
0%
Низкий
больше 14 лет назад
debian логотип
CVE-2011-1492

steps/utils/modcss.inc in Roundcube Webmail before 0.5.1 does not prop ...

CVSS2: 5.5
0%
Низкий
больше 14 лет назад
github логотип
GHSA-r646-w9ph-62w9

steps/utils/modcss.inc in Roundcube Webmail before 0.5.1 does not properly verify that a request is an expected request for an external Cascading Style Sheets (CSS) stylesheet, which allows remote authenticated users to trigger arbitrary outbound TCP connections from the server, and possibly obtain sensitive information, via a crafted request.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу