← Back

CVE-2013-6172

nvd nist
Published: Nov 5, 2013Modified: Apr 29, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

steps/utils/save_pref.inc in Roundcube webmail before 0.8.7 and 0.9.x before 0.9.5 allows remote attackers to modify configuration settings via the _session parameter, which can be leveraged to read arbitrary files, conduct SQL injection attacks, and execute arbitrary code.

Affected (54)

Products: Roundcube: Webmail
1 product
Webmail
Configuration A
54 vulnerable
Vulnerable SoftwareAffected Versions
Roundcube
Up to 0.8.6
Version 0.1.1
Version 0.1
Version 0.1 20050811
Version 0.1 20050820
Version 0.1 20051007
Version 0.1 20051021
Version 0.1 alpha
Version 0.1 beta2
Version 0.1 beta
Version 0.1 rc1
Version 0.1 rc2
Version 0.1 stable
Version 0.2.1
Version 0.2.2
Version 0.2
Version 0.2 alpha
Version 0.2 beta
Version 0.2 stable
Version 0.3.1
Version 0.3
Version 0.3 beta
Version 0.3 rc1
Version 0.3 stable
Version 0.4.1
Version 0.4.2
Version 0.4
Version 0.4 beta
Version 0.5.1
Version 0.5.2
Version 0.5.3
Version 0.5.4
Version 0.5
Version 0.5 beta
Version 0.5 rc
Version 0.6
Version 0.7.1
Version 0.7.2
Version 0.7.3
Version 0.7
Version 0.8.0
Version 0.8.1
Version 0.8.2
Version 0.8.3
Version 0.8.4
Version 0.8.5
Version 0.9.0
Version 0.9.1
Version 0.9.2
Version 0.9.3
Version 0.9.4
Version 0.9 beta
Version 0.9 rc2
Version 0.9 rc

Timeline

No history available yet.