Total vulnerabilities in the database
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
Software | From | Fixed in |
---|---|---|
roundcube / webmail | 1.3.0 | 1.3.11 |
roundcube / webmail | 1.4.0 | 1.4.4 |
roundcube / webmail | 1.2.0 | 1.2.10 |
opensuse / leap | 15.1 | 15.1.x |
opensuse / backports_sle | 15.0-sp1 | 15.0-sp1.x |
opensuse / leap | 15.2 | 15.2.x |
opensuse / backports_sle | 15.0-sp2 | 15.0-sp2.x |