Total vulnerabilities in the database
Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.
Software | From | Fixed in |
---|---|---|
roundcube / webmail | 1.3.0 | 1.3.11 |
roundcube / webmail | 1.4.0 | 1.4.4 |
roundcube / webmail | 1.2.0 | 1.2.10 |
opensuse / leap | 15.1 | 15.1.x |
opensuse / backports_sle | 15.0-sp1 | 15.0-sp1.x |
opensuse / leap | 15.2 | 15.2.x |
opensuse / backports_sle | 15.0-sp2 | 15.0-sp2.x |