Loading...
Loading...
steps/utils/save_pref.inc in Roundcube webmail before 0.8.7 and 0.9.x before 0.9.5 allows remote attackers to modify configuration settings via the _session parameter, which can be leveraged to read arbitrary files, conduct SQL injection attacks, and execute arbitrary code.
November 5, 2013
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2013-6172
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.